vendor:
Free MP3 CD Ripper
by:
Gionathan 'John' Reale
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Free MP3 CD Ripper
Affected Version From: 2.6
Affected Version To: 2.6
Patch Exists: YES
Related CWE: N/A
CPE: 2.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32bit
2018
Free MP3 CD Ripper 2.6 – ‘.mp3’ Buffer Overflow (SEH)
Free MP3 CD Ripper 2.6 is vulnerable to a buffer overflow vulnerability when a specially crafted .mp3 file is opened. This can be exploited to execute arbitrary code by overwriting the SEH handler with a pointer to malicious code.
Mitigation:
Upgrade to the latest version of Free MP3 CD Ripper 2.6 or apply the patch provided by the vendor.