WaveEditor 2, and possibly prior versions, fails to perform adequate boundary checks on user-supplied input when parsing malformed project (.wve) files causing a stack-based buffer overflow leading to possible remote code execution. WaveEditor will also included on Power2Go and PowerDirector installation.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
Solution
OSVDB is not aware of a solution for this vulnerability.