vendor:
Xion Audio Player
by:
condis
7,5
CVSS
HIGH
Denial of Service
399
CWE
Product Name: Xion Audio Player
Affected Version From: 1.0.127
Affected Version To: 1.0.127
Patch Exists: YES
Related CWE: N/A
CPE: a:xion_audio_player:xion_audio_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Professional PL
2009
Xion Audio Player 1.0.127 (.aiff) Denial of Service Vulnerability
Xion Audio Player 1.0.127 is vulnerable to a denial of service attack when a malicious .aiff file is opened. The malicious file contains a FORM header followed by a AIFFCOMM header and an 'A' character. When the file is opened, the program crashes due to an access violation while writing to 00000020.
Mitigation:
Update to the latest version of Xion Audio Player.