Impact
Practical Music Search version 0.42 has a stack‑based buffer overflow that can be triggered when a local, unauthenticated attacker supplies an oversized value in the configuration file. The overflow corrupts the stack and permits execution of arbitrary code using return‑oriented programming gadgets, giving the attacker full control of the process and potentially the host system.
Affected Systems
The vulnerability affects the Practical Music Search software, specifically the 0.42 release. No other versions are identified as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local file manipulation: an attacker must be able to create or modify the PMS configuration file, which typically requires write access to the filesystem. If such access is present, the attacker can trigger the overflow and achieve arbitrary code execution without authentication.
OpenCVE Enrichment