vendor:
AudioPLUS
by:
hack4love
7.5
CVSS
HIGH
Local buffer overflow
CWE
Product Name: AudioPLUS
Affected Version From: 2.00.215
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Pro SP2 (EN)
AudioPLUS 2.00.215 (.m3u / .lst File) Local buffer Overflow (seh)
The exploit is for AudioPLUS version 2.00.215 and it targets a buffer overflow vulnerability in the .m3u and .lst file formats. The exploit uses a specific sequence of characters to overflow the buffer, overwrite the structured exception handler (SEH) with a specific address, and execute shellcode. It has been tested on Windows XP Pro SP2 (EN).
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of AudioPLUS.