PT-2009-4126 · Mini Stream · Mini-Stream Asx To Mp3 Converter
G4N0K
·
Publicado
2009-05-15
·
Atualizado
2017-10-12
·
CVE-2009-1642
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mini-stream ASX to MP3 Converter version 3.0.0.7
Mini-stream ASX to MP3 Converter versions prior to 3.1.3.7
Description:
The issue is related to multiple stack-based buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved via a long rtsp URL in a .ram file or a long string in the HREF attribute of a REF element in a .asx file.
Recommendations:
For Mini-stream ASX to MP3 Converter version 3.0.0.7, update to version 3.1.3.7 or later to resolve the issue.
For Mini-stream ASX to MP3 Converter versions prior to 3.1.3.7, update to version 3.1.3.7 or later to resolve the issue.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mini-Stream Asx To Mp3 Converter