Description
MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload, paste it into the Server field via the CD menu's FreeDB Proxy Options, and trigger code execution when settings are accepted.
Problem types
Product status
3.1 (semver)
Credits
bzyo
References
www.exploit-db.com/exploits/46056 (ExploitDB-46056)
www.magix.com/us/ (Official Product Homepage)
www.magix.com/us/music/mp3-deluxe/ (Product Reference)
www.vulncheck.com/...ix-music-editor-buffer-overflow-via-seh (VulnCheck Advisory: MAGIX Music Editor 3.1 Buffer Overflow via SEH)