vendor:
TeraCopy
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Integer Overflow
CWE
Product Name: TeraCopy
Affected Version From: 2.27
Affected Version To: 2.3 beta 2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows Server 2008 R2 EN (64-bit), Microsoft Windows 7 Ultimate SP1 EN (32-bit)
2013
TeraCopy 2.3 (default.mo) Language File Integer Overflow Vulnerability
TeraCopy is prone to an integer overflow vulnerability because it fails to perform adequate boundary checks when reading language files. Successfully exploiting this issue may allow local attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions.
Mitigation:
Unknown