Digital Music Pad <= 8.2.3.3.4 Stack Buffer Overflow
36Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 8.4epss 0.4%
da publicação à arma0 dias
Publicada no NVD21 de ago.
metasploit17 de set.
probabilidade de exploração
0.4%top 65% das CVEs
exploração observada
nãonenhuma fonte reporta
Digital Music Pad v8.2.3.3.4 contains a stack-based buffer overflow vulnerability in its playlist file parser. When opening a .pls file containing an excessively long string in the File1 field, the application fails to properly validate input length, resulting in corruption of the Structured Exception Handler (SEH) on the stack. This flaw may allow an attacker to control execution flow when the file is opened, potentially leading to arbitrary code execution.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Digital Music Pad · Digital Music PadReferências
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/digital_music_pad_pls.rbhttps://web.archive.org/web/20100923154433/http://secunia.com:80/advisories/41519https://www.exploit-db.com/exploits/15134https://www.topshareware.com/Digital-Music-Pad-download-79446.htmhttps://www.vulncheck.com/advisories/digital-music-pad-stack-buffer-overflow