vendor:
CDex
by:
bzyo
7,8
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: CDex
Affected Version From: v1.96
Affected Version To: v1.96
Patch Exists: YES
Related CWE: N/A
CPE: a:cdex:cdex:1.96
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x32
2017
CDex 1.96 – Local Stack Buffer Overflow
CDex 1.96 (Unicode Build) is vulnerable to a local stack buffer overflow. An attacker can exploit this vulnerability by generating a crash.txt file, opening the application, going to options, settings, encoding, tags, and pasting the crash.txt contents in the picture text. This will cause the application to crash, resulting in a pointer to the next SEH record and no unicode ppr pointers.
Mitigation:
Update to the latest version of CDex 1.96 (Unicode Build)