vendor:
CastRipper
by:
bibi-info
7.5
CVSS
HIGH
Stack Buffer Overflow
121
CWE
Product Name: CastRipper
Affected Version From: 2.50.70
Affected Version To: 2.50.70
Patch Exists: NO
Related CWE:
CPE: a:castripper_project:castripper:2.50.70
Platforms Tested: Windows XP SP2
2009
CastRipper (.M3U) Stack BOF WinXP SP2 – C
This exploit takes advantage of a stack buffer overflow vulnerability in CastRipper version 2.50.70. It allows an attacker to execute arbitrary code by sending a specially crafted .M3U file. The exploit contains shellcode that spawns the Windows calculator (calc.exe).
Mitigation:
Update to a patched version of CastRipper.