Easy CD & DVD Cover Creator Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in Easy CD & DVD Cover Creator version 4.13. The issue resides in the serial number input field, where attackers can input a payload of approximately 6000 bytes. This oversized input triggers an application crash, causing a denial-of-service condition.
Impact
Exploitation of this vulnerability leads to a crash of the Easy CD & DVD Cover Creator application, causing a denial-of-service condition.
Reproduction
To reproduce this vulnerability, first create a text file named 'Evil.txt' containing a 6000-byte payload of repeated characters. After the file is created, open Easy CD & DVD Cover Creator and navigate to the serial number input field. Paste the contents of 'Evil.txt' into the field and press 'Continue'. The application will crash, demonstrating the denial-of-service condition.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
