Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/22922Â - | |
References | () http://secunia.com/advisories/23475Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23485Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23493Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23495Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23511Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23516Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23530Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23532Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23534Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23535Â - | |
References | () http://secunia.com/advisories/23536Â - | |
References | () http://secunia.com/advisories/23541Â - | |
References | () http://secunia.com/advisories/23542Â - | |
References | () http://secunia.com/advisories/23543Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23544Â - | |
References | () http://secunia.com/advisories/23546Â - | |
References | () http://secunia.com/advisories/23548Â - | |
References | () http://secunia.com/advisories/23550Â - | |
References | () http://secunia.com/advisories/23551Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23552Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23553Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23554Â - | |
References | () http://secunia.com/advisories/23557Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23558Â - | |
References | () http://secunia.com/advisories/23560Â - | |
References | () http://secunia.com/advisories/23561Â - | |
References | () http://secunia.com/advisories/23562Â - | |
References | () http://secunia.com/advisories/23565Â - | |
References | () http://secunia.com/advisories/23568Â - Vendor Advisory | |
References | () http://secunia.com/advisories/23745Â - | |
References | () http://secunia.com/advisories/23753Â - | |
References | () http://secunia.com/advisories/23795Â - | |
References | () http://secunia.com/advisories/25993Â - | |
References | () http://secunia.com/advisories/26046Â - | |
References | () http://secunia.com/advisories/26100Â - | |
References | () http://secunia.com/advisories/26101Â - | |
References | () http://secunia.com/advisories/28407Â - | |
References | () http://secunia.com/advisories/30406Â - | |
References | () http://secunia.com/advisories/30424Â - | |
References | () http://secunia.com/advisories/30439Â - | |
References | () http://secunia.com/advisories/30446Â - | |
References | () http://secunia.com/advisories/30447Â - | |
References | () http://secunia.com/advisories/30450Â - | |
References | () http://secunia.com/advisories/30459Â - | |
References | () http://secunia.com/blog/6/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-10/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-11/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-12/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-13/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-14/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-15/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-16/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-17/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-18/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-19/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-2/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-20/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-21/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-22/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-23/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-24/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-25/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-26/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-27/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-28/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-29/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-3/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-30/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-31/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-32/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-33/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-34/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-4/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-5/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-50/advisory/Â - | |
References | () http://secunia.com/secunia_research/2007-6/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-7/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-8/advisory/Â - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-9/advisory/Â - Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/292713Â - US Government Resource | |
References | () http://www.securityfocus.com/archive/1/457936/100/200/threaded - | |
References | () http://www.securityfocus.com/archive/1/457940/100/200/threaded - | |
References | () http://www.securityfocus.com/archive/1/457965/100/200/threaded - | |
References | () http://www.securityfocus.com/bid/22196Â - | |
References | () http://www.securityfocus.com/bid/23892Â - | |
References | () http://www.vupen.com/english/advisories/2007/0310Â - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/31707Â - |
Information
Published : 2007-01-24 21:28
Updated : 2024-11-21 00:24
NVD link : CVE-2007-0018
Mitre link : CVE-2007-0018
CVE.ORG link : CVE-2007-0018
JSON object : View
Products Affected
mystik_media_products
- blaze_mediaconvert
- blaze_media_pro
- audioedit_deluxe
- contextconvert_pro
mp3-soft
- mp3_normalizer
dandans_digital_media_products
- easy_audio_editor
- full_audio_converter
- music_editing_master
- visual_video_converter
mcfunsoft
- recording_to_ipod_solution
- ipod_music_converter
- ipod_audio_studio
- audio_studio
- audio_editor
- audio_recorder_for_free
j_hepple_products
- fx_audio_tools
- fx_movie_joiner
- fx_audio_concat
- fx_movie_splitter
- fx_audio_editor
- fx_new_sound
- fx_video_converter
- fx_magic_music
- fx_movie_joiner_and_splitter
roemer_software
- free_hi-q_recorder
- easy_hi-q_recorder
- easy_hi-q_converter
quikscribe
- quikscribe_recorder
- quikscribe_player
expstudio
- audio_editor
nextlevel_systems
- audio_editor_gold
- audio_studio_gold
recordnrip
- recordnrip
movavi
- convertmovie
- dvd_to_ipod
- splitmovie
- suite
- videomessage
- chiliburner
virtual_cd
- virtual_cd
- virtual_cd_file_server
imesh.com
- imesh
softdiv_softare
- dexster
- mp3_to_wav_converter
- ivideomax
- snosh
- videozilla
altdo
- mp3_record_and_edit_audio_master
- convert_mp3_master
cdburnerxp
- cdburnerxp_pro
xrlly_software
- arial_audio_converter
- text_to_speech_maker
- arial_sound_recorder
nctsoft_products
- nctaudioeditor
- nctaudiostudio
- nctdialogicvoice
- nctaudiofile2
magicvideosoftare
- magic_audio_recorder
- magic_music_editor
- magic_audio_converter
iaudiosoft.com
- absolute_video_to_audio_converter
- absolute_sound_recorder
- absolute_mp3_splitter
rmbsoft
- audioconvert
- soundedit_pro
xwaver.com
- magic_audio_editor_pro
- magic_music_studio_pro
easy_ringtone_maker
- easy_ringtone_maker
smart_media_systems
- power_audio_editor
audio_edit_magic
- audio_edit_magic
mediatox
- aurora_media_workshop
code-it_softare
- abasic_editor
- wave_mp3_editor
joshua_mediasoft
- video_converter_plus
- audio_convertor_plus
cheetahburner
- cheetah_dvd_burner
- cheetah_cd_burner
digital_borneo
- audio_mixer_and_editor
sienzo
- digital_music_mentor
bearshare
- bearshare
americanshareware
- mp3_wav_converter
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer