GHSA-jw6p-33r2-662fHighCVSS 8.4
Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file...
🔗 CVE IDs covered (1)
📋 Description
Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded through the Convert function, enabling execution of arbitrary code through ROP chain gadgets and shellcode injection.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25383
- https://www.exploit-db.com/exploits/45565
- https://www.vulncheck.com/advisories/free-mp3-cd-ripper-buffer-overflow-seh-dep-bypass
- http://www.commentcamarche.net/download/telecharger-34082200-free-mp3-cd-ripper
- https://github.com/advisories/GHSA-jw6p-33r2-662f