vendor:
ALLPlayer
by:
metacom
7,8
CVSS
HIGH
Buffer Overflow UNICODE
119
CWE
Product Name: ALLPlayer
Affected Version From: ALLPlayer 5.6.2
Affected Version To: ALLPlayer 5.6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:allplayer:allplayer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 German
2013
ALLPlayer Local Buffer Overflow PoC UNICODE
A buffer overflow vulnerability exists in ALLPlayer 5.6.2, which could allow an attacker to execute arbitrary code. The vulnerability is caused by a boundary error when handling a specially crafted .m3u file. By persuading a victim to open a specially crafted .m3u file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
Mitigation:
Upgrade to the latest version of ALLPlayer