vendor:
FoxPlayer
by:
Oh Yaw Theng
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: FoxPlayer
Affected Version From: 2.4.2000
Affected Version To: 2.4.2000
Patch Exists: NO
Related CWE:
CPE: a:foxmediatools:foxplayer:2.4.0
Platforms Tested: Windows XP SP2
2010
FoxPlayer 2.4.0 (.m3u) Denial of Service
This exploit targets FoxPlayer version 2.4.0 by sending a specially crafted .m3u file. It causes the application to crash due to a buffer overflow vulnerability.
Mitigation:
Update to a patched version of FoxPlayer or use an alternative media player.