Description
jetAudio 8.1.7.20702 Basic contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string through the URL input handler. Attackers can trigger the crash by pasting a buffer of 5000 characters into the Open URL dialog, causing the application to terminate abnormally.
Problem types
Use of Pointer Subtraction to Determine Size
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46810 (ExploitDB-46810)
www.jetaudio.com/ (Official Product Homepage)
www.jetaudio.com/download/ (Product Reference)
www.vulncheck.com/...basic-denial-of-service-via-url-handler (VulnCheck Advisory: jetAudio 8.1.7.20702 Basic Denial of Service via URL Handler)