vendor:
Euphonics Audio Player
by:
Houssamix
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Euphonics Audio Player
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE: N/A
CPE: a:euphonics:euphonics_audio_player:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Euphonics Audio Player v1.0 (.pls) Universal Local Buffer Overflow Exploit
Euphonics Audio Player v1.0 is vulnerable to a universal local buffer overflow exploit. The exploit is triggered when a specially crafted .pls file is opened. The exploit uses a jmp esp from AdjMmsEng.dll as the return address and a win32_exec payload to execute a calculator program. The exploit was first discovered by h4ck3r#47 and later modified by Houssamix to make it universal.
Mitigation:
The vendor has released a patch to address this vulnerability.