vendor:
Euphonics Audio Player
by:
h4ck3r#47
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Euphonics Audio Player
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:euphonics:euphonics_audio_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Pro Sp3 (English)
2009
Euphonics Audio Player v1.0 (.pls) Local Buffer Overflow Exploit
A local buffer overflow vulnerability exists in Euphonics Audio Player v1.0. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to a boundary error when handling .pls files. A specially crafted .pls file can cause a stack-based buffer overflow, overwriting the return address and allowing arbitrary code execution.
Mitigation:
Upgrade to the latest version of Euphonics Audio Player.