Description
Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.
Problem types
Sensitive Information in Resource Not Removed Before Reuse
Product status
Credits
Alejandra Sánchez
References
www.exploit-db.com/exploits/46816 (ExploitDB-46816)
lyricvideocreator.com/ (Official Product Homepage)
lyricvideocreator.com/dwl/LyricVideoCreator.exe (Product Reference)
www.vulncheck.com/...-creator-denial-of-service-via-mp3-file (VulnCheck Advisory: Lyric Video Creator 2.1 Denial of Service via MP3 File)