vendor:
KMPlayer
by:
Jigsaw (Abdelmorite Eljoaydi)
3,3
CVSS
LOW
Denial Of Service
N/A
CWE
Product Name: KMPlayer
Affected Version From: 3.5.00.77
Affected Version To: 3.5.00.77
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP1,SP2 and SP3 'Windows 7 is not Vulnerable' other OS maybe Vulnerable
2013
KMPlayer (PlayList M3U) Denial Of Service PoC All Versions
When creating a file with the poc below, you'll have to open the playlist file in kmplayer, a box will pop up just press OK. After that press the play button to trigger the DOS vulnerability. The program will not be able to respond until the process is killed using the task manager.
Mitigation:
N/A