vendor:
AnyBurn
by:
Dino Covotsos - Telspace Systems
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: AnyBurn
Affected Version From: 4.3 (32-bit)
Affected Version To: 4.3 (32-bit)
Patch Exists: NO
Related CWE: TBC from Mitre
CPE: //a:anyburn
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3 ENG x86
2019
AnyBurn x86 – Denial of Service (DoS)
AnyBurn x86 is vulnerable to Denial of Service (DoS) attack. An attacker can exploit this vulnerability by creating a malicious file containing a large number of 'A' characters and then paste the contents of the malicious file under 'Select source image file' and 'Select Destination image file' in the application. When the attacker clicks 'Convert Now', the program crashes.
Mitigation:
The vendor should patch the vulnerability by validating the input and sanitizing the user input.