Description
GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open URL dialog. Attackers can generate a specially crafted text file with Unicode-encoded shellcode to trigger a stack-based overflow and execute commands when the file is opened.
Problem types
Product status
Credits
Andy Bowden
References
www.exploit-db.com/exploits/48510 (ExploitDB-48510)
www.goldwave.com/ (Official Vendor Homepage)
www.vulncheck.com/...es/goldwave-buffer-overflow-seh-unicode (VulnCheck Advisory: GoldWave 5.70 – Buffer Overflow (SEH Unicode))