vendor:
SkinCrafter
by:
Saurabh Sharma
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SkinCrafter
Affected Version From: SkinCrafter version 3.0
Affected Version To: SkinCrafter version 3.0
Patch Exists: YES
Related CWE: CVE-2012-2271
CPE: a:nmsoft_technologies:skincrafter:3.0
Platforms Tested: Windows XP SP2
2012
Buffer overflow in skincrafter3_vs2005.dll of skinCrafter vs3.0
The vulnerability lies in the COM component used by the product SkinCrafter from DMSoft Technologies. This COM component, SkinCrafter3_vs2005.dll, implements a function InitLicenKeys, whose parameter is not checked for the bounds, hence leading to the overflow condition.
Mitigation:
Apply the latest patch or update to fix the buffer overflow vulnerability.