Summary
This host has Mini-Stream products installed and is prone to Buffer Overflow Vulnerability.
Impact
Successful exploitation allows attackers to execute arbitrary code or crash the system.
Impact Level: Application.
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore.
General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
Insight
A boundary error occurs in multiple Mini-stream products due to inadequate validation of user supplied data while processing playlist (.m3u) files with overly long URI.
Affected
Shadow Stream Recorder version 3.0.1.7 and prior on Windows RM-MP3 Converter version 3.0.0.7 and prior on Windows WM Downloader version 3.0.0.9 and prior on Windows RM Downloader version 3.0.0.9 and prior on Windows ASXtoMP3 Converter version 3.0.0.7 and prior on Windows Ripper version 3.0.1.1 and prior on Windows
References
Severity
Classification
-
CVE CVE-2009-1324, CVE-2009-1325, CVE-2009-1326, CVE-2009-1327, CVE-2009-1328, CVE-2009-1329 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Active Perl 'Perl_repeatcpy()' Function Buffer Overflow Vulnerability (Windows)
- Apple iTunes 'itms:' URI Stack Buffer Overflow Vulnerability
- Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
- Adobe Reader/Acrobat Multiple Vulnerabilities - Nov08 (Win)
- Adobe Reader/Acrobat Multiple BOF Vulnerabilities - Jun09 (Win)