vendor:
CONNECT Player
by:
TaMBaRuS
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CONNECT Player
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:sony:connect_player
Platforms Tested: Windows XP SP2/2k SP4
2007
Sony CONNECT Player M3U Playlist Processing Stack Buffer Overflow
This exploit takes advantage of a stack buffer overflow vulnerability in Sony CONNECT Player M3U Playlist Processing. It allows an attacker to execute arbitrary code on the target system by crafting a malicious M3U playlist file. The exploit was discovered by Parvez Anwar and written by TaMBaRuS. It has been tested on Sony CONNECT Player (SonicStage) 4.x installed on Windows XP SP2/2k SP4. The exploit contains shellcode that executes a Windows command provided by metasploit.com. This exploit is for educational purposes only.
Mitigation:
Upgrade to a patched version of Sony CONNECT Player.