Impact
This vulnerability allows a local attacker to crash the JetAudio application by supplying an excessively long string to its URL input handler. By entering a buffer of 5000 characters into the Open URL dialog, the application terminates abruptly, resulting in a loss of service for the user. The weakness is an uncontrolled memory allocation, evidencing CWE-469: Uncontrolled Memory Allocation.
Affected Systems
JetAudio products from Jetaudio, notably version 8.1.7.20702 and all earlier 8.0.x releases, are impacted. The flaw affects users who have the ability to enter URLs via the Open URL feature, regardless of operating system.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and no EPSS score is available. This vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation to date. The attack vector is local; an attacker must have physical or remote access sufficient to run the application and paste the oversized string. Consequently, the risk is confined to local or compromised users using JetAudio.
OpenCVE Enrichment