vendor:
Free MP3 CD Ripper
by:
Richard Leahy
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Free MP3 CD Ripper
Affected Version From: 2.6
Affected Version To: 2.6
Patch Exists: YES
Related CWE: N/A
CPE: a:free_mp3_cd_ripper:free_mp3_cd_ripper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2010
Free MP3 CD Ripper 2.6 (wav) 0-day
A buffer overflow vulnerability exists in Free MP3 CD Ripper 2.6 when a specially crafted WAV file is opened. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to insufficient boundary checks when processing WAV files. By sending a specially crafted WAV file, an attacker can cause a buffer overflow, which can be used to execute arbitrary code.
Mitigation:
Upgrade to the latest version of Free MP3 CD Ripper.