vendor:
Audio Player
by:
Mountassif Moad a.k.a Stack
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Audio Player
Affected Version From: 2.PLS
Affected Version To: 2.PLS
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
dBpowerAMP Audio Player Release 2.PLS Local Buffer Overflow Exploit
dBpowerAMP Audio Player Release 2.PLS contains a local buffer overflow vulnerability. The vulnerability is triggered when a specially crafted .pls file is opened, resulting in a stack overflow. The exploit is triggered by a 257 byte long string of A's, followed by a 1000 byte long string of A's for stack overflow, and a 3000 byte long string of A's for heap overflow.
Mitigation:
Users should avoid opening untrusted .pls files.