vendor:
VUPlayer
by:
Encrypt3d.M!nd
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VUPlayer
Affected Version From: 2.49
Affected Version To: 2.49
Patch Exists: YES
Related CWE: CVE-2009-0385
CPE: a:vup:vup_player:2.49
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-763-1/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-0698/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-0698/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-746-1/, https://www.rapid7.com/db/vulnerabilities/ffmpeg-cve-2009-0385/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-0385/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-6733e1bf-125f-11de-a964-0030843d3802/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
VUPlayer 2.49 .ASX File (Universal) Local Buffer Overflow Exploit
VUPlayer 2.49 is prone to a buffer overflow vulnerability when processing .ASX files. This vulnerability is due to a boundary error when copying user-supplied data into a fixed-length buffer. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of VUPlayer 2.49 or later.