vendor:
Easy MPEG to DVD Burner
by:
Marwan Shamel
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy MPEG to DVD Burner
Affected Version From: 1.7.11
Affected Version To: 1.7.11
Patch Exists: YES
Related CWE: N/A
CPE: a:easy-dvd-mpeg-converter:easy_mpeg_to_dvd_burner:1.7.11
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Enterprise SP1 32 bit
2018
Easy MPEG to DVD Burner 1.7.11 SEH Local Buffer Overflow
Easy MPEG to DVD Burner 1.7.11 is vulnerable to a local buffer overflow vulnerability. By supplying a specially crafted input, an attacker can overwrite the SEH handler and execute arbitrary code. The vulnerability is caused due to a boundary error when handling user-supplied input, specifically when handling the username field. This can be exploited to cause a stack-based buffer overflow by supplying a long string of data as the username. This will overwrite the SEH handler and allow the attacker to execute arbitrary code.
Mitigation:
Upgrade to the latest version of Easy MPEG to DVD Burner 1.7.11 or apply the patch provided by the vendor.