vendor:
SAP player
by:
Steven Seeley aka mr_me
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SAP player
Affected Version From: 0.9
Affected Version To: 0.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
SAP player 0.9 (.pla) Universal Local BoF Exploit (SEH)
This is a buffer overflow exploit for SAP player 0.9 (.pla) that allows for arbitrary code execution. It exploits a vulnerability in the software's handling of .pla files, triggering a stack-based buffer overflow. By crafting a malicious .pla file, an attacker can overwrite the SEH (Structured Exception Handler) and gain control of the program's execution flow.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of SAP player or use an alternative media player.