vendor:
ProShow Producer
by:
Julien Ahrens
6,9
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Stack-based Buffer Overflow [CWE-121]
121
CWE
Product Name: ProShow Producer
Affected Version From: Photodex ProShow Producer v5.0.3256
Affected Version To: Older versions may be affected too.
Patch Exists: NO
Related CWE: -
CPE: a:photodex:proshow_producer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Inshell Security Advisory
A Local Buffer Overflow Vulnerability has been found on the Photodex ProShow Producer v5.0.3256. When starting, the application loads the contents of the 'load' file from its application directory. The application does not validate the length of the string loaded from the 'load' file before passing it to a buffer, which leads to a Buffer Overflow. An attacker needs to force the victim to place an arbitrary 'load' file into the application directory.
Mitigation:
None