vendor:
EZ CD Audio Converter
by:
Achilles
7.8
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: EZ CD Audio Converter
Affected Version From: 8.0.7
Affected Version To: 8.0.7
Patch Exists: YES
Related CWE: N/A
CPE: a:poikosoft:ez_cd_audio_converter
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64
2018
EZ CD Audio Converter 8.0.7 – Denial of Service (PoC)
EZ CD Audio Converter 8.0.7 is vulnerable to a Denial of Service (DoS) attack due to a Local Buffer Overflow. The vulnerability can be triggered by running a python code that creates a file with a malicious payload of 10000 bytes, copying the content of the file to the clipboard, opening the EZ CD Audio Converter application, pasting the content of the file into the 'Key' field, and then observing a crash.
Mitigation:
Upgrade to the latest version of EZ CD Audio Converter