vendor:
StreamRipper32
by:
Andy Bowden
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: StreamRipper32
Affected Version From: 2.6
Affected Version To: 2.6
Patch Exists: YES
Related CWE: N/A
CPE: a:streamripper:streamripper32
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win10 x64
2020
StreamRipper32 2.6 – Buffer Overflow (PoC)
StreamRipper32 is a Windows application that allows users to record streaming audio from the Internet. A buffer overflow vulnerability exists in StreamRipper32 version 2.6 when a user adds a maliciously crafted string to the 'SongPattern' field in the 'Station/Song Section' of the application. This can be exploited to execute arbitrary code by a remote attacker.
Mitigation:
Upgrade to the latest version of StreamRipper32.