PT-2011-5190 · Tomatosoft · Tomatosoft Free Mp3 Player
Jamba
·
Published
2011-12-30
·
Updated
2017-08-29
·
CVE-2011-5043
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
TomatoSoft Free Mp3 Player version 1.0
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash, by using a long string in an MP3 file. This could be related to a buffer overflow.
Recommendations
For TomatoSoft Free Mp3 Player version 1.0, consider avoiding the use of MP3 files with long strings until a patch is available. As a temporary workaround, restrict the handling of MP3 files to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tomatosoft Free Mp3 Player