SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.
References
| Link | Resource |
|---|---|
| https://web.archive.org/web/20221207074555/https://www.sound4.com/ | Product |
| https://www.exploit-db.com/exploits/51259 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/sound-linkandshare-transmitter-format-string-stack-buffer-overflow | Exploit Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5744.php | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5744.php | Third Party Advisory |
Configurations
History
31 Dec 2025, 17:12
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Sound4 linkandshare Transmitter
Sound4 |
|
| References | () https://web.archive.org/web/20221207074555/https://www.sound4.com/ - Product | |
| References | () https://www.exploit-db.com/exploits/51259 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/sound-linkandshare-transmitter-format-string-stack-buffer-overflow - Exploit, Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5744.php - Third Party Advisory | |
| CPE | cpe:2.3:a:sound4:linkandshare_transmitter:1.1.2:*:*:*:*:*:*:* |
22 Dec 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-22 22:16
Updated : 2025-12-31 17:12
NVD link : CVE-2023-53966
Mitre link : CVE-2023-53966
CVE.ORG link : CVE-2023-53966
JSON object : View
Products Affected
sound4
- linkandshare_transmitter
CWE
CWE-134
Use of Externally-Controlled Format String
