A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges.
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
The product writes data past the end, or before the beginning, of the intended buffer.