vendor:
HTML5 Video Player
by:
T3jv1l
7.8
CVSS
HIGH
Denial of Service
119
CWE
Product Name: HTML5 Video Player
Affected Version From: 1.2.5
Affected Version To: 1.2.5
Patch Exists: YES
Related CWE: N/A
CPE: a:html5videoplayer:html5_video_player
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1 x86
2018
HTML5 Video Player 1.2.5 – Denial of Service (PoC)
A buffer overflow vulnerability exists in HTML5 Video Player 1.2.5, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to a boundary error when handling a specially crafted registration name. This can be exploited to cause a stack-based buffer overflow via an overly long, specially crafted registration name.
Mitigation:
Upgrade to the latest version of HTML5 Video Player.