Vulnerability Description
Magix Musik Maker 16 is vulnerable to a stack-based buffer overflow due to improper handling of .mmm arrangement files. The vulnerability arises from an unsafe strcpy() operation that fails to validate input length, allowing attackers to overwrite the Structured Exception Handler (SEH). By crafting a malicious .mmm file, an attacker can trigger the overflow when the file is opened, potentially leading to arbitrary code execution. This vulnerability was remediated in version 17.
Related Weaknesses (CWE)
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exp
- https://web.archive.org/web/20110503060356/https://www.corelan.be/index.php/foru
- https://www.darkreading.com/vulnerabilities-threats/another-researcher-hit-with-
- https://www.exploit-db.com/exploits/17313
- https://www.exploit-db.com/exploits/17329
- https://www.magix.com/us/music-editing/music-maker/
- https://www.vulncheck.com/advisories/magix-musik-maker-stack-based-buffer-overfl
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exp
- https://www.exploit-db.com/exploits/17313
- https://www.exploit-db.com/exploits/17329
FAQ
What is CVE-2011-10021?
CVE-2011-10021 is a documented vulnerability. Magix Musik Maker 16 is vulnerable to a stack-based buffer overflow due to improper handling of .mmm arrangement files. The vulnerability arises from an unsafe strcpy() operation that fails to validat...
How severe is CVE-2011-10021?
CVSS scoring is not yet available for CVE-2011-10021. Check NVD for updates.
Is there a patch for CVE-2011-10021?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.