vendor:
SOUND4 LinkAndShare Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Format String Stack Buffer Overflow
134
CWE
Product Name: SOUND4 LinkAndShare Transmitter
Affected Version From: 1.1.2002
Affected Version To: 1.1.2002
Patch Exists: NO
Related CWE:
CPE: sound4:linkandshare_transmitter:1.1.2
Platforms Tested: Windows 10
2022
SOUND4 LinkAndShare Transmitter 1.1.2 – Format String Stack Buffer Overflow
The application suffers from a format string memory leak and stack buffer overflow vulnerability because it fails to properly sanitize user supplied input when calling the getenv() function from MSVCR120.DLL resulting in a crash overflowing the memory stack and leaking sensitive information. The attacker can abuse the username environment variable to trigger and potentially execute code on the affected system.
Mitigation:
Apply the vendor's patch or update to the latest version.