The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target machine. A failure in exploitation leads to a denial of service.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.un4seen.com/ | vendor advisory |
https://github.com/staufnic/CVE/tree/master/CVE-2019-19513 | third party advisory exploit |