vendor:
Free MP3 CD Ripper
by:
mr_me
7.5
CVSS
HIGH
Stack Buffer Overflow
Stack Buffer Overflow
CWE
Product Name: Free MP3 CD Ripper
Affected Version From: Free MP3 CD Ripper version 2.6
Affected Version To: Free MP3 CD Ripper version 2.6
Patch Exists: NO
Related CWE: Unknown
CPE: Free_MP3_CD_Ripper:2.6
Platforms Tested: Windows XP sp3
Unknown
Free MP3 CD Ripper 2.6 (wav) 1day stack buffer overflow PoC exploit
This is a proof-of-concept exploit for a stack buffer overflow vulnerability in Free MP3 CD Ripper version 2.6 (wav). The vulnerability allows an attacker to execute arbitrary code by overflowing a buffer on the stack. The exploit is based on the discovery by Richard Leahy and was provided by mr_me. The exploit can be downloaded from the provided link. The platform for this exploit is Windows XP sp3.
Mitigation:
There is no known mitigation or remediation for this vulnerability. Users are advised to avoid using the affected software or to update to a patched version if available.