WinMPG iPod Convert Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in WinMPG iPod Convert version 3.0, specifically within the Register dialog. This vulnerability allows local attackers to cause a denial-of-service condition by sending an oversized payload. By pasting a large string of characters into the User Name and User Code fields, attackers can crash the application.
Impact
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash.
Reproduction
To reproduce this vulnerability, first create a text file named 'Evil.txt' containing a payload of approximately 6000 bytes. After generating this file, open WinMPG iPod Convert and navigate to the 'Register' dialog. Once there, paste the contents of 'Evil.txt' into the User Name and User Code fields. Click 'Ok' to trigger the crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
