vendor:
MooPlayer
by:
Tomislav Paskalev
9.3
CVSS
HIGH
SEH Buffer Overflow
119
CWE
Product Name: MooPlayer
Affected Version From: 1.3.2000
Affected Version To: 1.3.2000
Patch Exists: Yes
Related CWE: CVE-2015-0902
CPE: a:mooplayer:mooplayer:1.3.0
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 EN
2015
MooPlayer 1.3.0 ‘m3u’ SEH Buffer Overflow
MooPlayer 1.3.0 is vulnerable to a SEH buffer overflow vulnerability when a specially crafted m3u file is opened. The vulnerability is triggered when the application attempts to process a long string of data, which causes a buffer overflow and overwrites the SEH handler. This can be exploited to execute arbitrary code by redirecting the execution flow to a malicious payload.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of MooPlayer.