vendor:
Zortam MP3 Media Studio
by:
Anonymous
7,5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Zortam MP3 Media Studio
Affected Version From: 9.40
Affected Version To: 9.40
Patch Exists: NO
Related CWE: N/A
CPE: a:zortam:zortam_mp3_media_studio
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
Zortam MP3 Media Studio 9.40 Multiple Memory Corruption Vulnerabilities
Zortam MP3 Studio version 9.40 suffers from a memory corruption attack from two different malicious files. The first method is thru a .mp3 file which has its ID3 tags filled with long strings. The second method is a .m3u list which is loaded in to the player resulting in memory corruption of the whole application including Dr.Watson crashing along with the app.
Mitigation:
Ensure that the ID3 tags of the .mp3 files are not filled with long strings and that the .m3u list is not loaded into the MP3 Player.