Easy MP3 Downloader Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in Easy MP3 Downloader version 4.7.8.8. This vulnerability allows local attackers to cause the application to crash by entering an excessively long unlock code. Exploitation involves generating a file with 6000 'A' characters and pasting it into the Unlock Code field when the application starts, creating a denial-of-service condition.
Impact
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash.
Reproduction
To reproduce this vulnerability, download and install Easy MP3 Downloader version 4.7.8.8. After installation, run the application and select the option to enter a serial number. When prompted, paste the contents of a file named 'exploit.txt'—which should contain 6000 'A' characters—into the Unlock Code field. Click 'OK' to proceed, and the application will crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
