vendor:
Streaming Audio Player
by:
Stack
9,3
CVSS
HIGH
Stack-based buffer overflow
119
CWE
Product Name: Streaming Audio Player
Affected Version From: 0.9
Affected Version To: 0.9
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WinSp2 En / FR
2009
Streaming Audio Player 0.9 (.M3U File) Local Stack Core Exploit
This exploit is a stack-based buffer overflow vulnerability in the Streaming Audio Player 0.9. It allows an attacker to execute arbitrary code on the vulnerable system by sending a specially crafted .M3U file. The vulnerability is caused due to a boundary error when handling .M3U files, which can be exploited to cause a stack-based buffer overflow by sending a specially crafted .M3U file with an overly long string.
Mitigation:
Upgrade to the latest version of Streaming Audio Player 0.9 or later.