vendor:
Wav to MP3
by:
Vulnerability Laboratory Core Research Team
5,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Wav to MP3
Affected Version From: 1.1.0.0
Affected Version To: 1.1.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:boxoft:wav_to_mp3:1.1.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Boxoft Wav v1.1.0.0 – Buffer Overflow Vulnerability
A local buffer overflow vulnerability has been discovered in the official Boxoft Wav to MP3 (freeware) V1.1.0.0 software. The local vulnerability allows local attackers to overwrite the registers to compromise the local software system process. The classic unicode buffer overflow vulnerability is located in the `Add` function of the `Play` module. The vulnerability allows to overwrite the registers with a crafted unicode string.
Mitigation:
Update to the latest version of the software