vendor:
KMPlayer
by:
Unknown
7.5
CVSS
HIGH
Denial-of-Service
400
CWE
Product Name: KMPlayer
Affected Version From: 2.9.3.1210
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:kmplayer:kmplayer:2.9.3.1210
Platforms Tested: Windows
2007
Denial-of-Service Vulnerabilities in KMPlayer
KMPlayer is prone to multiple denial-of-service vulnerabilities when handling malformed AVI media files. Successfully exploiting this issue allows remote attackers to deny service to legitimate users.
Mitigation:
Update KMPlayer to a patched version or avoid opening AVI media files from untrusted sources.