vendor:
Storm M3U File Processing
by:
Lufeng Li and Qingshan Li of Neusoft Corporation
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Storm M3U File Processing
Affected Version From: Storm2012 3.10.4.21
Affected Version To: Storm2012 3.10.1.12
Patch Exists: YES
Related CWE: CNVD-2010-00752
CPE: a:baofeng:storm_m3u_file_processing
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XPSP3 Chinese Simplified
2010
BaoFeng Storm M3U File Processing Buffer Overflow Exploit
A buffer overflow vulnerability exists in BaoFeng Storm M3U File Processing, which could allow an attacker to execute arbitrary code on the vulnerable system. The vulnerability is due to insufficient boundary checks when processing specially crafted M3U files. An attacker can exploit this vulnerability by enticing a user to open a malicious M3U file, resulting in arbitrary code execution.
Mitigation:
Users should avoid opening untrusted M3U files. Additionally, users should update to the latest version of BaoFeng Storm M3U File Processing.