vendor:
Merak Media Player
by:
Encrypt3d.M!nd
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Merak Media Player
Affected Version From: 3.2
Affected Version To: 3.2
Patch Exists: YES
Related CWE: CVE-2009-0385
CPE: a:merak_software:merak_media_player
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-763-1/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-0698/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-0698/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-746-1/, https://www.rapid7.com/db/vulnerabilities/ffmpeg-cve-2009-0385/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-0385/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-6733e1bf-125f-11de-a964-0030843d3802/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Merak Media Player 3.2 Buffer Overflow Exploit(SEH)
Merak Media Player 3.2 is vulnerable to a buffer overflow vulnerability due to improper bounds checking of user-supplied data. An attacker can exploit this vulnerability by sending a specially crafted request containing an overly long string of data to the vulnerable application. This can result in arbitrary code execution in the context of the application.
Mitigation:
Upgrade to the latest version of Merak Media Player 3.2 or later.