vendor:
CastRipper
by:
Jordi Chancel
7,5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: CastRipper
Affected Version From: 2.50.70
Affected Version To: 2.50.70
Patch Exists: YES
Related CWE: N/A
CPE: a:castripper:castripper:2.50.70
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
CastRipper 2.50.70 : ASX playlist Stack Overflow Exploit
This exploit is for CastRipper 2.50.70, which is vulnerable to a stack overflow vulnerability. The exploit is written in Perl and uses a PexAlphaNum encoder to generate a shellcode. The exploit creates an ASX playlist file with a malicious URL containing the shellcode, which when opened in CastRipper, will execute the shellcode.
Mitigation:
Update to the latest version of CastRipper