PT-2011-5190 · Tomatosoft · Tomatosoft Free Mp3 Player

Jamba

·

Published

2011-12-30

·

Updated

2017-08-29

·

CVE-2011-5043

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions TomatoSoft Free Mp3 Player version 1.0
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, by using a long string in an MP3 file. This could be related to a buffer overflow.
Recommendations For TomatoSoft Free Mp3 Player version 1.0, consider avoiding the use of MP3 files with long strings until a patch is available. As a temporary workaround, restrict the handling of MP3 files to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5043

Affected Products

Tomatosoft Free Mp3 Player