vendor:
OtsAv DJ & TV
by:
Mountassif Moad a.k.a Stack
7,8
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: OtsAv DJ & TV
Affected Version From: OtsAv DJ & TV prior to version 1.85.076
Affected Version To: OtsAv DJ & TV version 1.85.076 and earlier
Patch Exists: YES
Related CWE: N/A
CPE: a:otszone:otsav_dj
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
OtsAv DJ & TV [.olf] Local Heap Overflow Poc
OtsAv DJ & TV are vulnerable to a local heap overflow vulnerability. An attacker can exploit this vulnerability by creating a malicious .olf file containing a large number of 'A' or '45' characters and then importing it as a playlist. This will cause a heap overflow and can lead to arbitrary code execution.
Mitigation:
Users should update to the latest version of OtsAv DJ & TV to ensure that they are not vulnerable to this exploit.