InputMapper Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in InputMapper version 1.6.10, specifically within the username field. This vulnerability allows local attackers to cause the application to crash by entering an excessively long string. Exploitation involves copying a large payload into the username field and double-clicking to process it, which triggers the application to crash, resulting in a denial-of-service condition.
Impact
Exploitation of this vulnerability causes the application to crash, leading to a denial-of-service condition.
Reproduction
To reproduce this vulnerability, start InputMapper and log in as a guest. Once logged in, copy a large payload, approximately 15,000 characters long, into the username field. After pasting the payload, double-click on the username field to process it, which will cause the application to crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
