vendor:
MediaMonkey
by:
Alejandra Sánchez
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: MediaMonkey
Affected Version From: 4.1.23.1881
Affected Version To: 4.1.23.1881
Patch Exists: YES
Related CWE: N/A
CPE: a:ventis_media:mediamonkey:4.1.23.1881
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
MediaMonkey 4.1.23 – URL Denial of Service (PoC)
MediaMonkey 4.1.23 is vulnerable to a denial of service attack when a specially crafted MP3 file is opened. The vulnerability is triggered when a user opens a specially crafted MP3 file with a long URL. This causes the application to crash.
Mitigation:
Upgrade to the latest version of MediaMonkey.