Project64 Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in Project64 version 2.3.2, specifically within the Plugin Directory settings field. This vulnerability allows local attackers to crash the application by entering an excessively long string. By inputting a 6000-byte payload into the Plugin Directory field through the Options > Settings > Directories interface, attackers can trigger an application crash when the settings are reopened.
Impact
Exploitation of this vulnerability causes the application to crash, leading to a denial-of-service condition.
Reproduction
To reproduce this vulnerability, open Project64 version 2.3.2 on a Windows 7 32-bit system. Navigate to 'Options' > 'Settings' > 'Directories'. Paste a 6000-byte payload into the 'Plugin Directory' field and ensure it is selected. Click 'Apply' and then 'OK'. Reopen the 'Options' > 'Settings' menu to observe the application crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
