vendor:
HT-MP3Player
by:
hack4love <= (friend), His0k4
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: HT-MP3Player
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Pro SP3 (EN)
Unknown
HT-MP3Player 1.0 (.ht3) Universal Buffer Overflow (SEH)
The HT-MP3Player 1.0 (.ht3) application is vulnerable to a universal buffer overflow, specifically a stack-based buffer overflow. This vulnerability can be exploited to execute arbitrary code by crafting a malicious .ht3 file and triggering the overflow. The exploit takes advantage of a SEH (Structured Exception Handler) overwrite to gain control of program execution flow. The payload used in the exploit is a shellcode that executes the 'calc' program. This exploit has been tested on Windows XP Pro SP3 (EN).
Mitigation:
To mitigate this vulnerability, users should avoid opening or playing untrusted .ht3 files from unknown sources. It is recommended to update to a patched version of HT-MP3Player if available.