---
id: CVE-2018-25224
title: >-
  PMS 0.42 contains a stack-based buffer overflow vulnerability that allows
  local unauthenticated attackers to execute arbitrary code by supplying
  malicious values in the configuration file
summary: >-
  PMS 0.42 contains a stack-based buffer overflow vulnerability that allows
  local unauthenticated attackers to execute arbitrary code by supplying
  malicious values in the configuration file. Attackers can craft configuration
  files with ove…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: kimtore
product: practical_music_search
affected:
  - practical_music_search <= 0.42
published: '2026-03-28'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25224'
references:
  - url: 'https://pms.sourceforge.net'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/44426'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pms-stack-based-buffer-overflow-via-configuration-file
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00191
epssPercentile: 0.08004
ingestedAt: '2026-10-07T08:20:03.908Z'
---

## Overview

PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets.

## Affected

- `practical_music_search <= 0.42`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
