vendor:
Audacity
by:
Houssamix
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Audacity
Affected Version From: 1.2.2006
Affected Version To: 1.2.2006
Patch Exists: YES
Related CWE: N/A
CPE: audacity
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2009
Audacity 1.2.6 (.gro file ) Local buffer overflow POC
When a .gro file containing long Chars is imported in Audacity 1.2.6, the program will crash and the EAX, ECX, EDX, EBX, ESP, EBP, ESI, EDI and EIP registers will be overwritten. This can be exploited to execute arbitrary code by creating a malicious .gro file and importing it in Audacity.
Mitigation:
Update to the latest version of Audacity.