CVE-2019-25571

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ventismedia:mediamonkey:4.1.23.1881:*:*:*:*:windows:*:*

History

24 Mar 2026, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:ventismedia:mediamonkey:4.1.23.1881:*:*:*:*:windows:*:*
First Time Ventismedia
Ventismedia mediamonkey
Summary
  • (es) MediaMonkey 4.1.23 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales colapsar la aplicación al abrir un archivo MP3 especialmente diseñado que contiene una cadena de URL excesivamente larga. Los atacantes pueden crear un archivo MP3 malicioso con un búfer que contiene 4000 bytes de datos adjuntos a una URL, lo que hace que la aplicación colapse cuando el archivo se abre a través del diálogo Archivo > Abrir URL.
References () https://www.exploit-db.com/exploits/46378 - () https://www.exploit-db.com/exploits/46378 - Exploit, Third Party Advisory, VDB Entry
References () https://www.mediamonkey.com/ - () https://www.mediamonkey.com/ - Product
References () https://www.mediamonkey.com/sw/MediaMonkey_4.1.23.1881.exe - () https://www.mediamonkey.com/sw/MediaMonkey_4.1.23.1881.exe - Product
References () https://www.vulncheck.com/advisories/mediamonkey-denial-of-service-via-malformed-url - () https://www.vulncheck.com/advisories/mediamonkey-denial-of-service-via-malformed-url - Third Party Advisory

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-03-24 20:41


NVD link : CVE-2019-25571

Mitre link : CVE-2019-25571

CVE.ORG link : CVE-2019-25571


JSON object : View

Products Affected

ventismedia

  • mediamonkey
CWE
CWE-226

Sensitive Information in Resource Not Removed Before Reuse