vendor:
Sure Thing Disc Labeler
by:
Chance Johnson
7,8
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Sure Thing Disc Labeler
Affected Version From: 6.2.138.0
Affected Version To: 6.2.138.0
Patch Exists: YES
Related CWE: N/A
CPE: a:sure_thing:sure_thing_disc_labeler
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64 / Windows 10
2017
Sure Thing Disc Labeler – Stack Buffer Overflow (PoC)
A stack buffer overflow vulnerability exists in Sure Thing Disc Labeler 6.2.138.0. An attacker can exploit this vulnerability by creating a specially crafted project template file which when opened by the user, can lead to a return pointer being overwritten giving control over EIP when the function returns.
Mitigation:
Upgrade to the latest version of Sure Thing Disc Labeler