vendor:
Spotify
by:
Claes Spett and LiquidWorm
7,5
CVSS
HIGH
Memory Exhaustion
119
CWE
Product Name: Spotify
Affected Version From: 0.8.2.610
Affected Version To: 0.8.2.610.g090a06f8
Patch Exists: YES
Related CWE: N/A
CPE: a:spotify:spotify
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN) (32bit), Microsoft Windows 7 Ultimate SP1 (EN) (64bit)
2012
Spotify 0.8.2.610 (search func) Memory Exhaustion Exploit
The vulnerability is caused due to the Search box function not checking the boundary of user input. This can be exploited to cause a DoS due to memory exhaustion when inserting a long string of bytes (~80mil B / 80 MB) into the Search field in the GUI.
Mitigation:
Upgrade to the latest version of Spotify.