vendor:
Media Player
by:
Encrypt3d.M!nd
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Media Player
Affected Version From: 4.2.2001
Affected Version To: 4.2.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:rosoft:media_player:4.2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Rosoft Media Player 4.2.1 Local Buffer Overflow Exploit(0-day)
There is a buffer overflow vulnerability in Rosoft Media Player 4.2.1 which affects all supported types (m3u, rml, txt) and all versions. The exploit involves writing a malicious file with a large number of characters followed by an address containing 0, NOT 0x00, and then the EIP and shellcode.
Mitigation:
Update to the latest version of Rosoft Media Player.