vendor:
jetAudio
by:
SYS 49152
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: jetAudio
Affected Version From: jetAudio 7.0.5
Affected Version To: jetAudio 7.0.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 ENG
jetAudio 7.0.5 COWON Media Center MP4 Stack Overflow
This exploit allows an attacker to execute arbitrary code on a system running jetAudio 7.0.5 COWON Media Center MP4. The vulnerability is caused by a stack overflow in the AVI file parser of the media player. By crafting a malicious AVI file and playing it with COWON Media Center, an attacker can trigger the stack overflow and execute arbitrary code with the privileges of the user running the media player. This exploit has been tested on Windows XP SP2 ENG and provides a shell on port 49152.
Mitigation:
Update to a patched version of jetAudio. Currently, no patch is available.