vendor:
Free CD to MP3 Converter
by:
C4SS!0 G0M3S
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Free CD to MP3 Converter
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:eusing_software:free_cd_to_mp3_converter
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 EN (VMWARE FUSION - Version 3.1.1)
2010
Free CD to MP3 Converter 3.1 Buffer Overflow Exploit (SEH)
Free CD to MP3 Converter 3.1 is vulnerable to a buffer overflow exploit. The vulnerability is triggered when a specially crafted WAV file is opened. This exploit uses a SEH overwrite to execute arbitrary code. The exploit code contains a shellcode that will launch calc.exe when executed.
Mitigation:
The vendor has released a patch to address this vulnerability.