vendor:
MP3 CD Burner
by:
n00b
N/A
CVSS
HIGH
Buffer-Overflow
120
CWE
Product Name: MP3 CD Burner
Affected Version From: 4.32
Affected Version To: 4.32
Patch Exists: NO
Related CWE: Not provided
CPE: a:acoustica:mp3_cd_burner:4.32
Platforms Tested: Windows XP SP2
2007
Acoustica MP3 CD Burner 4.32 local buffer-overflow
Acoustica MP3 CD Burner 4.32 is prone to a buffer-overflow vulnerability when parsing a .asx playlist file. An attacker can entice a user to open a specially crafted .asx playlist file, allowing the execution of arbitrary shell code. This vulnerability occurs because the application fails to properly check boundaries on user-supplied data before copying it to an insufficiently sized memory buffer.
Mitigation:
The vendor should update Acoustica MP3 CD Burner to properly validate user-supplied data and prevent buffer-overflow vulnerabilities. Users should avoid opening untrusted .asx playlist files.