Description
Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long unlock code. Attackers can generate a file containing 6000 'A' characters and paste the contents into the Unlock Code field during application startup to trigger a denial of service condition.
Problem types
Product status
4.7.8.8
Credits
Mohan Ravichandran & Snazzy Sanoj
References
www.exploit-db.com/exploits/47319 (ExploitDB-47319)
download.cnet.com/...P3-Downloader/3000-2141_4-10860695.html (Product Reference)
www.vulncheck.com/...oader-denial-of-service-buffer-overflow (VulnCheck Advisory: Easy MP3 Downloader 4.7.8.8 Denial of Service Buffer Overflow)