CVE-2007-0018

UnknownEPSS 35.16%

Last modified

CVE-2007-0018 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. EPSS estimates a 35.16% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.

Metrics

EPSS Probability
35.16%

98.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AltdoConvert Mp3 Master1.1
AltdoMp3 Record And Edit Audio Master1.2
AmericansharewareMp3 Wav Converter3.1.8
Audio Edit MagicAudio Edit Magic9.2.3_389
BearshareBearshare6.0.2.26789
CdburnerxpCdburnerxp Pro3.0.116
CheetahburnerCheetah Cd Burner3.56
CheetahburnerCheetah Dvd Burner1.79
Code-It SoftareAbasic Editor10.1
Code-It SoftareWave Mp3 Editor10.1
Dandans Digital Media ProductsEasy Audio Editor7.4
Dandans Digital Media ProductsFull Audio Converter4.2
Dandans Digital Media ProductsMusic Editing Master5.2
Dandans Digital Media ProductsVisual Video Converter4.4
Digital BorneoAudio Mixer And Editor1.1.0
Easy Ringtone MakerEasy Ringtone Maker2.0.5
ExpstudioAudio Editor4.0.2
Iaudiosoft.ComAbsolute Mp3 Splitter2.5.4
Iaudiosoft.ComAbsolute Sound Recorder3.4.5
Iaudiosoft.ComAbsolute Video To Audio Converter2.7.9
Imesh.ComImesh7.0.2.26789
J Hepple ProductsFx Audio Concat1.2.0_beta
J Hepple ProductsFx Audio Editor4.7.11
J Hepple ProductsFx Audio Tools7.3.4
J Hepple ProductsFx Magic Music5.7.7
J Hepple ProductsFx Movie Joiner6.2.8
J Hepple ProductsFx Movie Joiner And Splitter6.2.8
J Hepple ProductsFx Movie Splitter6.4.7
J Hepple ProductsFx New Sound5.1.1
J Hepple ProductsFx Video Converter7.51.21
Joshua MediasoftAudio Convertor Plus2.2
Joshua MediasoftVideo Converter Plus3.01
MagicvideosoftareMagic Audio Converter8.2.6_build_719
MagicvideosoftareMagic Audio Recorder5.3.7
MagicvideosoftareMagic Music Editor5.2.2
McfunsoftAudio Editor6.3.3_build_489
McfunsoftAudio Recorder For Free6.1
McfunsoftAudio Studio6.6.3_build_479
McfunsoftIpod Audio Studio6.2.4
McfunsoftIpod Music Converter5.1
McfunsoftRecording To Ipod Solution5.1
MediatoxAurora Media Workshop3.3.25
MovaviChiliburner2.3
MovaviConvertmovie4.4
MovaviDvd To Ipod1.0
MovaviSplitmovie1.4
MovaviSuite3.5
MovaviVideomessage1.0
Mp3-SoftMp3 Normalizer1.03
Mystik Media ProductsAudioedit Deluxe4.10

Showing 50 of 83 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-0018?
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.
How severe is CVE-2007-0018?
Severity scoring for CVE-2007-0018 is pending analysis. The EPSS model estimates a 35.16% probability of exploitation in the next 30 days.
How do I fix CVE-2007-0018?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-0018?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST