vendor:
Bs.Player
by:
Nine:Situations:Group::pyrokinesis
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Bs.Player
Affected Version From: v2.32 Build 975 Free
Affected Version To: v2.34 Build 980 PRO
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Pro SP2/SP3, Windows 2003 SP1
Bs.Player <= 2.34 Build 980 (.bsl) local buffer overflow 0day exploit (seh)
Overlong hostnames in bsplayer playlist files causes eax and seh handlers to be overwritten. Cannot reliably debug with olly because of code compression, just used faultmon/memdump/msfpescan and I choosed the easy/universal way with seh. There are some pop ret addresses in common among the vulnerable versions...