CVE-2019-25560
HIGHLyric Video Creator 2.1 Denial of Service via MP3 File
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25560. PoCs published by Alejandra Sánchez.
AI-analyzed exploit summary This PoC demonstrates a denial-of-service vulnerability in Lyric Video Creator 2.1 by creating a malformed MP3 file with a large buffer of 'A' characters, causing the application to crash upon file selection.
Description
Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.
Exploits (1)
This PoC demonstrates a denial-of-service vulnerability in Lyric Video Creator 2.1 by creating a malformed MP3 file with a large buffer of 'A' characters, causing the application to crash upon file selection.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H