vendor:
CDex
by:
Nine:Situations:Group::Pyrokinesis
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CDex
Affected Version From: CDex v1.70b2
Affected Version To: CDex v1.70b2
Patch Exists: NO
Related CWE: Not provided
CPE: a:cdex_project:cdex:1.70b2
Platforms Tested: Windows XP SP3
Not provided
CDex v1.70b2 (.ogg) local buffer overflow exploit poc (win xp sp3)
A reliable buffer overflow exists in the way cdex process Ogg Vorbis Info headers. The exploit creates an evil.ogg file which, when played in CDex, triggers the buffer overflow.
Mitigation:
Apply the latest patch or update to a non-vulnerable version of CDex. Avoid playing untrusted media files in CDex.