Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.
Link | Tags |
---|---|
http://securitytracker.com/id?1013727 | vdb entry |
http://www.unl0ck.org/files/papers/winhex.txt | url repurposed |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20139 | vdb entry |