vendor:
Free MP3 CD Ripper
by:
Eduard Palisek
7.8
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Free MP3 CD Ripper
Affected Version From: 2.8 Build 20140611
Affected Version To: 2.8 Build 20140611
Patch Exists: YES
Related CWE: N/A
CPE: a:cleanersoft:free_mp3_cd_ripper
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP, Professional, Version 2002, SP 3
2020
Free MP3 CD Ripper 2.8 – Stack Buffer Overflow (SEH + Egghunter)
Free MP3 CD Ripper 2.8 is vulnerable to a stack buffer overflow vulnerability when a long string is passed to the application. This can be exploited to execute arbitrary code by corrupting the SEH chain and using an egghunter to locate the shellcode.
Mitigation:
Update to the latest version of Free MP3 CD Ripper 2.8