vendor:
HT-MP3Player
by:
hack4love, His0k4, jduck
7.5
CVSS
HIGH
Stack buffer overflow
119
CWE
Product Name: HT-MP3Player
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2009-2485
CPE: a:ht-mp3player:ht-mp3player:1.0
Platforms Tested: Windows
2009
HT-MP3Player 1.0 HT3 File Parsing Buffer Overflow
This module exploits a stack buffer overflow in HT-MP3Player 1.0. Arbitrary code execution could occur when parsing a specially crafted .HT3 file. NOTE: The player installation does not register the file type to be handled. Therefore, a user must take extra steps to load this file.
Mitigation:
Apply the vendor patch or update to a newer version of the software. Do not open untrusted .HT3 files.