vendor:
GOM Player
by:
Mountassif Moad
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: GOM Player
Affected Version From: 2.0.12
Affected Version To: 2.0.12
Patch Exists: YES
Related CWE: N/A
CPE: a:gomlab:gom_player:2.0.12
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
GOM Player 2.0.12 (.PLS) Universal Buffer Overflow Exploit
GOM Player 2.0.12 is vulnerable to a buffer overflow vulnerability when processing specially crafted .PLS files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This exploit was discovered and exploited by Mountassif Moad and was reported by Parvez Anwar in Secuina. The vulnerability Poc was reported by Parvez Anwar in Secuina and was exploited by DATA_SNIPER in milw0rm. This exploit is a new exploit for .PLS files and was inspired by DATA_SNIPER.
Mitigation:
Upgrade to the latest version of GOM Player.