vendor:
AVS Media Player
by:
metacom
7,8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: AVS Media Player
Affected Version From: 4.1.11.100
Affected Version To: 4.1.11.100
Patch Exists: YES
Related CWE: N/A
CPE: a:online_media_technologies:avs_media_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013
AVS Media Player(.ac3)Denial of Service Exploit
AVS Media Player version 4.1.11.100 is vulnerable to a denial of service attack when a specially crafted .ac3 file is opened. The file contains a buffer of bytes followed by a large amount of junk data and a small amount of bob data. When the file is opened, the application crashes.
Mitigation:
Update to the latest version of AVS Media Player