Vulnerability Description
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alivemedia | Alive Mp3 Wav Converter | 3.9.3.2 |
| Online Media Technologies | Nctaudioeditor Activex Control | All versions |
| Online Media Technologies | Nctaudiostudio Activex Control | All versions |
| Orion Studios | Cinematicmp3 | 1.4.0.0 |
| Ussun | Power Audio Cd Burner | 1.02 |
| Ussun | Power Audio Cd Grabber | 1.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/30395
- http://secunia.com/advisories/30415Vendor Advisory
- http://secunia.com/advisories/30418
- http://secunia.com/advisories/30419
- http://secunia.com/advisories/30421
- http://secunia.com/advisories/30445
- http://secunia.com/advisories/30451
- http://secunia.com/advisories/30452
- http://secunia.com/advisories/30453
- http://secunia.com/advisories/30454
- http://secunia.com/advisories/30456
- http://secunia.com/advisories/30457
- http://secunia.com/advisories/30458
- http://www.kb.cert.org/vuls/id/669265US Government Resource
- http://www.vupen.com/english/advisories/2008/1669
FAQ
What is CVE-2008-0959?
CVE-2008-0959 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Au...
How severe is CVE-2008-0959?
CVE-2008-0959 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0959?
Check the references section above for vendor advisories and patch information. Affected products include: Alivemedia Alive Mp3 Wav Converter, Online Media Technologies Nctaudioeditor Activex Control, Online Media Technologies Nctaudiostudio Activex Control, Orion Studios Cinematicmp3, Ussun Power Audio Cd Burner.