vendor:
FLVPlayer4Free
by:
KedAns-Dz
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FLVPlayer4Free
Affected Version From: 2.9.2000
Affected Version To: 2.9.2000
Patch Exists: NO
Related CWE:
CPE: a:flvplayer4free:flvplayer4free:2.9.0
Platforms Tested: Windows
FLVPlayer4Free v2.9 (.fp4f) Stack Overflow
FLVPlayer4Free is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input. Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Mitigation:
Update to a patched version of the software. Avoid providing untrusted input to the application.