Vulnerability Description
Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious payload exceeding 780 bytes, paste it into the License Name registration field, and trigger the overflow when the Register button is clicked.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alloksoft | Video Splitter | 3.1.1217 |
Related Weaknesses (CWE)
References
- http://www.alloksoft.com/Product
- https://www.exploit-db.com/exploits/44605ExploitVDB Entry
- https://www.vulncheck.com/advisories/allok-video-splitter-buffer-overflow-via-liThird Party Advisory
FAQ
What is CVE-2018-25211?
CVE-2018-25211 is a vulnerability with a CVSS score of 7.8 (HIGH). Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the Licens...
How severe is CVE-2018-25211?
CVE-2018-25211 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25211?
Check the references section above for vendor advisories and patch information. Affected products include: Alloksoft Video Splitter.