PT-2019-19858 · Koyote Soft · Free Mp3 Cd Ripper

Gionathan Reale

+1

·

Published

2019-03-14

·

Updated

2020-11-20

·

CVE-2019-9767

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Free MP3 CD Ripper version 2.6
Description The issue is a stack-based buffer overflow that occurs when converting a file, allowing remote attackers to execute arbitrary code via a crafted .wma file. This can be exploited when a user assists the attack, such as by opening a malicious file.
Recommendations For Free MP3 CD Ripper version 2.6, avoid converting .wma files from untrusted sources until a patch is available. As a temporary workaround, consider disabling the file conversion feature to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9767

Affected Products

Free Mp3 Cd Ripper