vendor:
Easy Music Player
by:
hack4love
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy Music Player
Affected Version From: 1.0.0.2
Affected Version To: 1.0.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:otbcode:easy_music_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH)
Easy Music Player 1.0.0.2 is vulnerable to a buffer overflow vulnerability when a specially crafted .pls file is opened. This can be exploited to execute arbitrary code by corrupting the stack and overwriting the SEH handler. The exploit code is written in Perl and contains a payload of shellcode.
Mitigation:
Upgrade to the latest version of Easy Music Player 1.0.0.2