PT-2010-3929 · D.R. · D.R. Software Audio Converter

Chap0

·

Published

2010-06-21

·

Updated

2017-08-17

·

CVE-2010-2343

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D.R. Software Audio Converter versions 8.1, 8.05, and 2007
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a crafted pls playlist file.
Recommendations For version 8.1, update to a version that fixes the stack-based buffer overflow issue. For version 8.05, update to a version that fixes the stack-based buffer overflow issue. For version 2007, update to a version that fixes the stack-based buffer overflow issue. As a temporary workaround, consider avoiding the use of crafted pls playlist files until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2343

Affected Products

D.R. Software Audio Converter