vendor:
XMPlay
by:
s7acktrac3
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: XMPlay
Affected Version From: 3.8.2003
Affected Version To: 3.8.2003
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP/7/8
2018
XMPlay 3.8.3 – ‘.m3u’ Denial of Service (PoC)
The exploit allows an attacker to crash the XMPlay media player by providing a specially crafted '.m3u' file. By launching XMPlay and either dragging the 'xmplay.m3u' file into the XMPlay window or selecting 'winamp.m3u' from the File menu, the application will crash.
Mitigation:
Update to a patched version of XMPlay or use an alternative media player.