vendor:
Sonique Player
by:
Securityxxxpert
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sonique Player
Affected Version From: 1.96
Affected Version To: 1.96
Patch Exists: Yes
Related CWE: N/A
CPE: a:sonique:sonique_player:1.96
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2011
Sonique BOF EIP Overwrite
This exploit is for the Sonique Player application version 1.96. It is a buffer overflow exploit that overwrites the EIP with 239 bytes of data and Pita Bytes of 0x00 0x83 0x88 0x93. It is not universal and the user must find their own offsets if not using Windows XP SP3 Eng. The exploit includes 4 Nops before aligning the stack in order to align the stack properly without errors. It then creates a directory and a text file with the exploit code in it.
Mitigation:
The user should update to the latest version of the Sonique Player application.