vendor:
FreeAmp Music Player
by:
Iván García Ferreira
N/A
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: FreeAmp Music Player
Affected Version From: 2.0.7
Affected Version To: 2.0.7
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2011
FreeAmp 2.0.7 .fat Buffer Overflow
The freeamp music player has a tool to create your own theme. If you go to "tools" directory in the Freeamp's directory you can see the "MakeTheme.exe" tool. With this command: c:FreeampTools> MakeTheme -d ..themesFreeamp.fat you uncompress the freeamp's theme. Then, you can see and a lot of files that the tool needs to make the theme. If you write a very long string in the "title.txt" file and you generate a new theme with: c:FreeampTools> MakeTheme exploit.fat theme.xml title.txt *.bmp When the user try to test the new theme called "exploit", it will generate a buffer overflow vulnerability.
Mitigation:
Apply the latest patch or update to FreeAmp version 2.0.8 or higher.