vendor:
GOM Player
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: GOM Player
Affected Version From: 2.1.6.3499
Affected Version To: 2.1.6.3499
Patch Exists: NO
Related CWE:
CPE: a:gomlab:gom_player:2.1.6.3499
Platforms Tested: Windows XP SP2 with Internet Explorer 6
Unknown
GOM Player GomWeb Control Remote Buffer Overflow PoC Exploit
This is a proof-of-concept exploit for a remote buffer overflow vulnerability in GOM Player's GomWeb Control component. By passing more than 506 characters to the OpenUrl method, an attacker can trigger a buffer overflow and potentially execute arbitrary code.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid opening untrusted media files or visiting malicious websites.