vendor:
Beatport Player
by:
SirGod The Discover
7,8
CVSS
HIGH
Stack Core Overflow Exploit(SEH)
119
CWE
Product Name: Beatport Player
Affected Version From: 1.0.0.283
Affected Version To: 1.0.0.283
Patch Exists: Yes
Related CWE: N/A
CPE: a:beatport:beatport_player:1.0.0.283
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Beatport Player 1.0.0.283 (.M3U File) Stack Core Overflow Exploit(SEH)
Beatport Player 1.0.0.283 is vulnerable to a stack core overflow exploit. This exploit works only on Windows SP2 FR. The exploit is written in Perl and uses a win32_exec shellcode to execute a command. The exploit creates a malicious .m3u file which contains a junk payload, a next_seh, a seh, a nopsled, and a shellcode.
Mitigation:
Update to the latest version of Beatport Player.