HIGH · 7.8

CVE-2017-8367

Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burn...

Vulnerability Description

Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD Burner, MP3 WAV to CD Burner, My Video Converter, Easy AVI DivX Converter, Easy Video to iPod Converter, Easy Video to PSP Converter, Easy Video to 3GP Converter, Easy Video to MP4 Converter, and Easy Video to iPod/MP4/PSP/3GP Converter allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long username.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Ether SoftwareEasy Avi\/Divx\/Xvid To Dvd Burner-
Ether SoftwareEasy Avi Divx Converter-
Ether SoftwareEasy Cd Dvd Copy-
Ether SoftwareEasy Dvd Creator-
Ether SoftwareEasy Mov Converter-
Ether SoftwareEasy Mpeg\/Avi\/Divx\/Wmv\/Rm To Dvd-
Ether SoftwareEasy Mpeg To Dvd Burner-
Ether SoftwareEasy Rm Rmvb To Dvd Burner-
Ether SoftwareEasy Video To 3Gp Converter-
Ether SoftwareEasy Video To Ipod\/Mp4\/Psp\/3Gp Converter-
Ether SoftwareEasy Video To Ipod Converter-
Ether SoftwareEasy Video To Mp4 Converter-
Ether SoftwareEasy Video To Psp Converter-
Ether SoftwareEasy Wmv\/Asf\/Asx To Dvd Burner-
Ether SoftwareMp3\/Avi\/Mpeg\/Wmv\/Rm To Audio Cd Burner-
Ether SoftwareMp3\/Wav\/Ogg\/Wma\/Ac3 To Cd Burner-
Ether SoftwareMp3 Wav To Cd Burner-
Ether SoftwareMy Video Converter-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-8367?

CVE-2017-8367 is a vulnerability with a CVSS score of 7.8 (HIGH). Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burn...

How severe is CVE-2017-8367?

CVE-2017-8367 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-8367?

Check the references section above for vendor advisories and patch information. Affected products include: Ether Software Easy Avi\/Divx\/Xvid To Dvd Burner, Ether Software Easy Avi Divx Converter, Ether Software Easy Cd Dvd Copy, Ether Software Easy Dvd Creator, Ether Software Easy Mov Converter.