vendor:
MP3 WAV to CD Burner
by:
Anurag Srivastava
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: MP3 WAV to CD Burner
Affected Version From: 1.4.24
Affected Version To: 1.4.24
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 x64
2017
MP3 WAV to CD Burner 1.4.24 – ‘Enter User Name’ Field Buffer Overflow (SEH)
The 'Enter User Name' field in MP3 WAV to CD Burner version 1.4.24 is vulnerable to a buffer overflow attack. This can be exploited by pasting a large amount of data into the field, causing the program to crash or potentially execute arbitrary code.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users should avoid using the 'Enter User Name' field with large amounts of data or disable the affected software.