Vulnerability Description
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as originally reported for Euphonics Audio Player 1.0. NOTE: some of these details are obtained from third party information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Multimediasoft | Audio Dj Studio For .Net | - |
| Multimediasoft | Audio Sound Editer For .Net | - |
| Multimediasoft | Audio Sound Recorder For .Net | - |
| Multimediasoft | Audio Sound Studio For .Net | - |
| Multimediasoft | Audio Sound Suite For .Net | - |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/33791Vendor Advisory
- http://secunia.com/advisories/33817Vendor Advisory
- http://www.securityfocus.com/archive/1/500652/100/0/threaded
- http://www.securityfocus.com/bid/33589
- http://www.vupen.com/english/advisories/2009/0316
- https://www.exploit-db.com/exploits/7958
- https://www.exploit-db.com/exploits/7973
- https://www.exploit-db.com/exploits/7974
- http://secunia.com/advisories/33791Vendor Advisory
- http://secunia.com/advisories/33817Vendor Advisory
- http://www.securityfocus.com/archive/1/500652/100/0/threaded
- http://www.securityfocus.com/bid/33589
- http://www.vupen.com/english/advisories/2009/0316
- https://www.exploit-db.com/exploits/7958
- https://www.exploit-db.com/exploits/7973
FAQ
What is CVE-2009-0476?
CVE-2009-0476 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary c...
How severe is CVE-2009-0476?
CVE-2009-0476 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0476?
Check the references section above for vendor advisories and patch information. Affected products include: Multimediasoft Audio Dj Studio For .Net, Multimediasoft Audio Sound Editer For .Net, Multimediasoft Audio Sound Recorder For .Net, Multimediasoft Audio Sound Studio For .Net, Multimediasoft Audio Sound Suite For .Net.