vendor:
ALLPlayer
by:
Mike Czumak
7.5
CVSS
HIGH
SEH Buffer Overflow
121
CWE
Product Name: ALLPlayer
Affected Version From: 5.6.2002
Affected Version To: 5.6.2002
Patch Exists: NO
Related CWE:
CPE: a:allplayer:allplayer:5.6.2
Platforms Tested: Windows XP SP3
2013
ALLPlayer 5.6.2 (.m3u) – SEH Buffer Overflow (Unicode)
This exploit targets a SEH buffer overflow vulnerability in ALLPlayer 5.6.2. By opening a specially crafted .m3u file, an attacker can trigger the vulnerability and execute arbitrary code.
Mitigation:
Update to a non-vulnerable version of ALLPlayer.