vendor:
Bsplayer
by:
fady_osman
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Bsplayer
Affected Version From: Windows XP SP1
Affected Version To: Windows 8 Enterprise
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP1, Windows 7 SP1, Windows 8 Enterprise
Buffer Overflow Vulnerability in Bsplayer
Bsplayer suffers from a buffer overflow vulnerability when processing the HTTP response when opening a URL. In order to exploit this bug, the seh record is partially overwritten to land at pop pop ret instead of the full address, and then backward jumping is used to jump to a long jump that eventually lands in the shellcode.
Mitigation:
Apply the latest patch provided by the vendor.