PT-2009-5486 · Aimp · Aimp2 Audio Converter
Mr_Me
·
Publicado
2009-09-11
·
Atualizado
2017-09-19
·
CVE-2009-3170
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AIMP2 Audio Converter versions 2.53 (build 330) and earlier
Description
The issue is a stack-based buffer overflow that can be triggered by a long
File1 argument in a .pls or .m3u playlist file, potentially allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code.Recommendations
For AIMP2 Audio Converter versions 2.53 (build 330) and earlier, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this issue. As a temporary workaround, consider restricting the use of
.pls and .m3u playlist files to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aimp2 Audio Converter