vendor:
WAV to MP3 Converter
by:
Robbie Corley, Shelby Pace
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: WAV to MP3 Converter
Affected Version From: 1
Affected Version To: 1.1
Patch Exists: NO
Related CWE: CVE-2015-7243
CPE: a:boxoft:wav_to_mp3_converter:1.0, cpe:/a:boxoft:wav_to_mp3_converter:1.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apachemodphp-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/php-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/php-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2015-4026/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apachemodphp-cve-2015-4025/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-alas-2015-534/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-alas-2015-535/, https://www.rapid7.com/db/?q=CVE-2015-7243&type=&page=2, https://www.rapid7.com/db/?q=CVE-2015-7243&type=&page=2
Platforms Tested: Windows
2015
Boxoft WAV to MP3 Converter v1.1 Buffer Overflow
This module exploits a stack buffer overflow in Boxoft WAV to MP3 Converter versions 1.0 and 1.1. By constructing a specially crafted WAV file and attempting to convert it to an MP3 file in the application, a buffer is overwritten, which allows for running shellcode.
Mitigation:
Apply the vendor's patch or upgrade to a newer version of the software.