vendor:
VUPlayer
by:
Not provided
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: VUPlayer
Affected Version From: Version 2.49
Affected Version To: Version 2.49
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Not provided
Not provided
VUPlayer Local Stack Overflow
This exploit demonstrates a local stack overflow vulnerability in VUPlayer version 2.49. The vulnerability can be triggered by opening a specially crafted .asx file. The exploit code provided causes a stack overflow by sending a long string of A characters. This can lead to remote code execution or a denial of service condition.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to avoid opening untrusted .asx files with VUPlayer.