COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
BID:27698
Info
COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27698 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0747 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | laurent gaffie discovered this vulnerability. |
| Vulnerable: |
COWON America jetAudio Plus 7.1.9 .4030 COWON America jetAudio Basic 8.0.2 COWON America jetAudio Basic 7.0.3 |
| Not Vulnerable: | |
Discussion
COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
jetAudio is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer while processing ASX, WAX, or WVX files.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
The following are vulnerable:
jetAudio 7.0.5 and 8.0.2
jetAudio Plus 7.1.9.4030
Other versions may also be affected.
jetAudio is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer while processing ASX, WAX, or WVX files.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
The following are vulnerable:
jetAudio 7.0.5 and 8.0.2
jetAudio Plus 7.1.9.4030
Other versions may also be affected.
Exploit / POC
COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to process a maliciously crafted file.
The following exploits are available:
To exploit this issue, an attacker must entice an unsuspecting user to process a maliciously crafted file.
The following exploits are available:
Solution / Fix
COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
References:
References: