vendor:
DivX Plus Web Player
by:
Snake (Shahriyar.j)
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: DivX Plus Web Player
Affected Version From: 2.1.2.265
Affected Version To: 2.1.2.265
Patch Exists: YES
Related CWE: Not Assigned Yet
CPE: a:divx:divx_plus_web_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: XP SP3, IE6
2011
DivX Plus Web Player “file://” Buffer Overflow Vulnerability PoC ( 0day )
This is a proof-of-concept exploit for a buffer overflow vulnerability in DivX Plus Web Player version 2.1.2.265 and earlier. The bug is triggered when a maliciously crafted file:// URL is passed to the vulnerable application. This can lead to arbitrary code execution.
Mitigation:
Upgrade to the latest version of DivX Plus Web Player