vendor:
BlazeDVD
by:
Parvez Anwar and Greg Linares
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: BlazeDVD
Affected Version From: 5
Affected Version To: 5
Patch Exists: Yes
Related CWE: CVE-2006-6706
CPE: a:blazevideo:blazedvd:5.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP SP2 (English)
2006
BlazeDVD 5.0 PLF Playlist File Remote Buffer Overflow Exploit (PoC)
BlazeDVD 5.0 suffers from buffer overflow vulnerability that can be exploited via crafted PLF playlist file locally and remotely. It fails to perform boundary checking of the user input file, allowing the EIP to be overwritten, thus, controlling the next instruction of the software. After successful exploitation, calc.exe will be executed. Failed attempts will result in Denial Of Service (DoS).
Mitigation:
Upgrade to the latest version of BlazeDVD 5.0