vendor:
WinMerge
by:
Thingamahoochie Software
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: WinMerge
Affected Version From: 2.12.4.0 Unicode
Affected Version To: 2.12.4.0 Unicode
Patch Exists: Yes
Related CWE: N/A
CPE: a:thingamahoochie:winmerge:2.12.4.0_unicode
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2009
WinMerge v2.12.4 Project File Handling Stack Overflow Vulnerability
WinMerge version 2.12.4 suffers from a stack overflow vulnerability because it fails to properly sanitize user supplied input when parsing .winmerge project file format resulting in a crash overflowing the memory stack. The attacker can use this scenario to lure unsuspecting users to open malicious crafted .winmerge files with a potential for arbitrary code execution on the affected system.
Mitigation:
Update to the latest version of WinMerge.