vendor:
GoldWave
by:
Andy Bowden
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: GoldWave
Affected Version From: 5.7
Affected Version To: 5.7
Patch Exists: YES
Related CWE:
CPE: a:goldwave:goldwave
Platforms Tested: Windows 10 x86
2020
GoldWave 5.70 Buffer Overflow (SEH Unicode)
GoldWave 5.70 is vulnerable to a buffer overflow vulnerability when a specially crafted file is opened. This can be exploited to execute arbitrary code by corrupting the SEH chain and overwriting the return address with a pointer to the malicious code. The vulnerability is triggered when a user opens a specially crafted file with the application.
Mitigation:
Upgrade to the latest version of GoldWave 5.70 or later.