vendor:
MooPlayer
by:
Samandeep Singh (SaMaN - @samanL33T)
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: MooPlayer
Affected Version From: 1.3.2000
Affected Version To: 1.3.2000
Patch Exists: YES
Related CWE: N/A
CPE: a:mooplayer:mooplayer:1.3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Win 7 x86
2015
MooPlayer 1.3.0 ‘m3u’ SEH Buffer Overflow POC
MooPlayer 1.3.0 is vulnerable to a SEH buffer overflow vulnerability. The vulnerability is triggered when a specially crafted m3u file is opened in the application. The SEH chain is overwritten with the value of nSEH and SEH, and the stack is filled with the value of AAAA. The registers are also overwritten with the value of CCCC and nSEH.
Mitigation:
Update to the latest version of MooPlayer 1.3.0