vendor:
Chasys Media Player
by:
Stack
7.5
CVSS
HIGH
Stack Overflow
Unknown
CWE
Product Name: Chasys Media Player
Affected Version From: Chasys Media Player 1.1
Affected Version To: Chasys Media Player 1.1
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Chasys Media Player 1.1 .cue file Stack Overflow Exploit
This exploit targets Chasys Media Player 1.1 by exploiting a stack overflow vulnerability in the .cue file parser. The attacker can craft a specially crafted .cue file that, when opened by the vulnerable media player, will trigger the stack overflow and potentially allow the execution of arbitrary code. This exploit has been written in Ruby and can be used to gain unauthorized access to a target system.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid opening .cue files from untrusted sources or using an alternative media player until a patch is available.