vendor:
RarmaRadio
by:
chuyreds
7.8
CVSS
HIGH
Denial of Service (DoS) Local
400
CWE
Product Name: RarmaRadio
Affected Version From: 2.72.4
Affected Version To: 2.72.4
Patch Exists: NO
Related CWE: N/A
CPE: a:raimersoft:rarmaradio
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
RarmaRadio 2.72.4 – ‘server’ Denial of Service (PoC)
RarmaRadio 2.72.4 is vulnerable to a denial of service attack when a maliciously crafted server name is provided. By providing a server name of 4000 'A' characters, the application will crash when the user attempts to save the settings.
Mitigation:
Users should avoid providing untrusted input to the application and should ensure that all input is properly validated.