vendor:
My Video Converter
by:
Anurag Srivastava
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: My Video Converter
Affected Version From: 1.5.24
Affected Version To: 1.5.24
Patch Exists: NO
Related CWE:
CPE: cpe:2.3:a:divxtodvd:my_video_converter:1.5.24:*:*:*:*:*:*:*
Platforms Tested: Windows 7 x64
2017
My Video Converter 1.5.24 – ‘Enter User Name’ Field Buffer Overflow (SEH)
This exploit targets the 'Enter User Name' field in My Video Converter 1.5.24. By entering a specially crafted string, it triggers a buffer overflow vulnerability, corrupting the Structured Exception Handler (SEH) chain. This can potentially allow an attacker to execute arbitrary code.
Mitigation:
The vendor should release a patch that fixes the buffer overflow vulnerability and validates user input to prevent malicious code execution.