vendor:
Abyssal Metal Player
by:
41.w4r10r
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Abyssal Metal Player
Affected Version From: 2.0.9
Affected Version To: 2.0.9
Patch Exists: NO
Related CWE: N/A
CPE: a:abyssalsoft:abyssal_metal_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 Eng
2010
Abyssal Metal Player 2.0.9 DoS
Abyssal Metal Player is Media File Player which Plays many Media Files such as .Mp3 , .avi, .mov, .mpg, .wav. This vulnerability is found in playing avi file format. An attacker can create a malicious avi file with a large amount of data and when the user opens the file in the player, the application will crash and the user will not be able to use the system until it is restarted.
Mitigation:
The user should not open any suspicious files from untrusted sources.