PT-2010-3929 · D.R. · D.R. Software Audio Converter
Chap0
·
Published
2010-06-21
·
Updated
2017-08-17
·
CVE-2010-2343
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D.R. Software Audio Converter versions 8.1, 8.05, and 2007
Description
The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a crafted pls playlist file.
Recommendations
For version 8.1, update to a version that fixes the stack-based buffer overflow issue.
For version 8.05, update to a version that fixes the stack-based buffer overflow issue.
For version 2007, update to a version that fixes the stack-based buffer overflow issue.
As a temporary workaround, consider avoiding the use of crafted pls playlist files until a patch is available.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D.R. Software Audio Converter