CVE-2009-4656
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
03/03/2010
Last modified:
11/04/2025
Description
Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a playlist file (.pls) containing a long string. NOTE: some of these details are obtained from third party information.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:e-soft.co:dj_studio_pro:4.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:e-soft.co:dj_studio_pro:4.2.2.7.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:e-soft.co:dj_studio_pro:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:e-soft.co:dj_studio_pro:5.1.4.3.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/36728
- http://www.exploit-db.com/exploits/9691
- http://www.vupen.com/english/advisories/2009/2681
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53310
- http://secunia.com/advisories/36728
- http://www.exploit-db.com/exploits/9691
- http://www.vupen.com/english/advisories/2009/2681
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53310



