Description
Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter technique to achieve remote code execution on vulnerable Windows systems.
Problem types
Product status
Credits
Eduard Palisek
References
www.exploit-db.com/exploits/48696 (ExploitDB-48696)
www.cleanersoft.com (Vendor Homepage)
www.vulncheck.com/...per-stack-buffer-overflow-seh-egghunter (VulnCheck Advisory: Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter))