TaskInfo Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A local buffer overflow vulnerability has been identified in TaskInfo version 8.2.0.280. This vulnerability allows attackers to cause a denial-of-service condition by inputting excessively long strings into the New User Name or New Serial Number fields in the registration dialog under the Help menu. The overflow occurs when the application processes the oversized input, leading to a crash.
Impact
Exploitation of this vulnerability causes the application to crash, creating a denial-of-service condition.
Reproduction
To reproduce this vulnerability, open TaskInfo 8.2.0.280 and navigate to the Help menu. Select 'Registration' and then 'Set or View Registration Information'. Paste a long string into the 'New User Name' and 'New Serial Number' textboxes. Click the OK button, which will trigger the application to crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
