vendor:
Digital Music Pad
by:
Abhishek Lyall
7,8
CVSS
HIGH
SEH overflow
119
CWE
Product Name: Digital Music Pad
Affected Version From: 8.2.3.4.8
Affected Version To: 8.2.3.4.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:digital_music_pad:digital_music_pad:8.2.3.4.8
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
Unknown
Digital Music Pad Version 8.2.3.4.8 SEH overflow
A SEH overflow vulnerability exists in Digital Music Pad Version 8.2.3.4.8. An attacker can exploit this vulnerability to execute arbitrary code by sending a specially crafted .pls file. The vulnerability is due to the application not properly validating the length of user-supplied input before copying it to a fixed-length buffer. An attacker can exploit this vulnerability to execute arbitrary code by sending a specially crafted .pls file.
Mitigation:
Upgrade to the latest version of Digital Music Pad.