vendor:
Easy MP3 Downloader
by:
Mohan Ravichandran & Snazzy Sanoj
5.5
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: Easy MP3 Downloader
Affected Version From: 4.7.8.8
Affected Version To: 4.7.8.8
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2019
Easy MP3 Downloader Denial of Service
This exploit code creates a file 'exploit.txt' with a large amount of junk data (6000 bytes). When this file is copied and pasted into the Unlock Code field of the Easy MP3 Downloader application, it causes the application to crash.
Mitigation:
The vendor should release a patch that limits the size of input accepted in the Unlock Code field to prevent crashes.