vendor:
Quick Player
by:
Felipe Winsnes
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Quick Player
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE:
CPE: a:quick_player:quick_player:1.3
Platforms Tested: Windows 7
2020
Quick Player 1.3 – ‘.m3l’ Buffer Overflow (Unicode & SEH)
The exploit takes advantage of a buffer overflow vulnerability in Quick Player version 1.3. By creating a specially crafted '.m3l' file and loading it into the application, an attacker can execute arbitrary code and gain control over the affected system.
Mitigation:
Update to a patched version of Quick Player or use an alternative media player. Avoid opening untrusted '.m3l' files.