This application requires Javascript for optimal performance.

Free.MP3.CD.Ripper.Buffer.Overflow

Release Date

Jun 17, 2010

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer-overflow vulnerability in Free MP3 CD Ripper.

The vulnerability is caused by an error when the vulnerable software handles a malicious .wav file. It allows a remote attacker to execute arbitrary code via sending a crafted wav file.

Affected Products

Free MP3 CD Ripper 2.6 is vulnerable. Other versions may also be affected.

Recommended Actions

Do not convert untrusted WAV files.

Coverage

IPS
VCM

Reference/s

http://www.securityfocus.com/bid/39672 (BugTraq)

Reference: VID-23214