vendor:
Multimedia Player
by:
0in aka zer0in from Dark-Coders Group
7.5
CVSS
HIGH
Heap-based buffer-overflow
119
CWE
Product Name: Multimedia Player
Affected Version From: Nokia Multimedia Player 1.1
Affected Version To: Nokia Multimedia Player 1.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP sp3
2008
Nokia Multimedia Player version 1.1 .m3u Heap Overflow PoC exploit
Nokia Multimedia Player is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions.
Mitigation:
Ensure that user-supplied input is properly validated and sanitized.