vendor:
Soritong MP3 Player
by:
Jacky
9.3
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Soritong MP3 Player
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE: N/A
CPE: a:soritong:soritong_mp3_player:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2020
Soritong MP3 Player 1.0 Universal BOF
This exploit is for Soritong MP3 Player 1.0 Universal BOF vulnerability. It is a buffer overflow vulnerability which allows an attacker to execute arbitrary code by overflowing the buffer with malicious code. The exploit is written in Python and uses a PPR from a .dll application file. It also uses additional NOPs for additional protection.
Mitigation:
The best way to mitigate this vulnerability is to update the Soritong MP3 Player to the latest version and ensure that all security patches are applied.