vendor:
DVD X Player
by:
n00b
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DVD X Player
Affected Version From: DVD X Player 4.1 Professional
Affected Version To: DVD X Player 4.1 Professional
Patch Exists: NO
Related CWE:
CPE: a:intervideo:windvd
Platforms Tested: Windows XP Service Pack 2
0day DVD X Player 4.1 Professional .PLF file buffer overflow
DVD X Player 4.1 Professional is prone to a buffer-overflow vulnerability when playing an overly long file name inside a .plf file. This file is used as a playlist file by both InterVideo WinDVD and DVD X Player. The vulnerability allows for a potential SEH overwrite, leading to remote code execution. Tested on Windows XP Service Pack 2.
Mitigation:
Update to a patched version of DVD X Player. Avoid opening untrusted .plf files.