vendor:
RarmaRadio
by:
chuyreds
7.5
CVSS
HIGH
Denial of Service (DoS) Local
20
CWE
Product Name: RarmaRadio
Affected Version From: 2.72.4
Affected Version To: 2.72.4
Patch Exists: YES
Related CWE: N/A
CPE: a:raimersoft:rarmaradio
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
RarmaRadio 2.72.4 – ‘username’ Denial of Service (PoC)
RarmaRadio 2.72.4 is vulnerable to a denial of service attack when a maliciously crafted username is used. By running the python code 'rarmaradio_username.py', a text file containing a buffer of 5000 'A' characters is created. When this text file is copied to the clipboard and pasted into the 'Username' field in the 'Network' settings, the application will crash.
Mitigation:
Upgrade to the latest version of RarmaRadio.