vendor:
CORE Multimedia Suite 2011 CORE Player
by:
Rh0[at]z1p.biz
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CORE Multimedia Suite 2011 CORE Player
Affected Version From: 2.4
Affected Version To: 2.4
Patch Exists: NO
Related CWE:
CPE: CORE Multimedia Suite 2011 CORE Player 2.4
Platforms Tested: Windows XP Pro SP3 EN (VirtualBox)
2011
CORE Multimedia Suite 2011 CORE Player 2.4 Unicode SEH Buffer Overflow Exploit (.m3u)
This exploit takes advantage of a buffer overflow vulnerability in CORE Multimedia Suite 2011 CORE Player 2.4. By loading a malicious playlist, an attacker can trigger the overflow and potentially execute arbitrary code.
Mitigation:
Remove the 'Load.m3l' file to prevent the exploit from triggering.