vendor:
VideoSpirit Pro
by:
xsploitedsec
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VideoSpirit Pro
Affected Version From: v1.68
Affected Version To: v1.68
Patch Exists: NO
Related CWE:
CPE: videospirit_pro:1.68
Platforms Tested: Windows XP SP3 Eng
2011
VideoSpirit Pro v1.68 Local BoF Exploit
VideoSpirit Pro is prone to a buffer overflow when parsing a (.visprj) project file that contains an overly long 'mp3' value. This is because the application fails to properly bounds check the data before it is passed to strcpy().
Mitigation:
Apply the latest patch or update to a non-vulnerable version of the software.