vendor:
yahoo! player
by:
D3r K0n!G
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: yahoo! player
Affected Version From: 1.5
Affected Version To: 1.5.01.409
Patch Exists: NO
Related CWE:
CPE: a:yahoo:yahoo!_player:1.5.01.409
Platforms Tested: Windows XP SP3
2011
yahoo! player 1.5 (.m3u) Universal Buffer Overflow (SEH)
This exploit takes advantage of a buffer overflow vulnerability in yahoo! player version 1.5.01.409. By crafting a specially crafted .m3u file, an attacker can trigger a buffer overflow and execute arbitrary code on the target system. The exploit uses a short jump instruction followed by a POP POP RET sequence to overwrite the Structured Exception Handler (SEH) and gain control of the program flow. The exploit payload contains shellcode that spawns a calculator application. This vulnerability has been tested on Windows XP SP3.
Mitigation:
To mitigate this vulnerability, users are advised to update to a patched version of yahoo! player or uninstall the software if it is no longer needed.