vendor:
Extended Module Player
by:
Luigi Auriemma
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Extended Module Player
Affected Version From: Extended Media Player 2.5.1
Affected Version To: Extended Media Player 2.5.1
Patch Exists: NO
Related CWE:
CPE: a:extended_module_player_project:extended_module_player:2.5.1
Platforms Tested:
2007
Extended Module Player Buffer Overflow
Extended Module Player (xmp) is prone to multiple local buffer-overflow vulnerabilities because it fails to perform adequate boundary checks before copying user-supplied input into an insufficiently sized buffer.These issues occur when the application handles specially crafted OXM and DTT files.Attackers can exploit these issues to execute arbitrary code that could compromise the affected computer. Failed attacks will likely cause denial-of-service conditions.Extended Media Player 2.5.1 is vulnerable; other versions may also be affected.
Mitigation:
Update to the latest version of Extended Module Player to address these vulnerabilities.