vendor:
Lyric Maker
by:
Alejandra Sánchez
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Lyric Maker
Affected Version From: 2.0.1.0
Affected Version To: 2.0.1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:jetaudio:lyric_maker:2.0.1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
Lyric Maker 2.0.1.0 – Denial of Service (PoC)
A denial of service vulnerability exists in Lyric Maker 2.0.1.0 due to a buffer overflow when copying a large amount of data to the 'Title' field. An attacker can exploit this vulnerability by running a python script to generate a text file with a large amount of data, copying the data to the clipboard, pasting it into the 'Title' field, and then saving the file. This will cause the application to crash.
Mitigation:
Upgrade to the latest version of Lyric Maker 2.0.1.0 or later.