vendor:
XBMC
by:
n00b
8.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: XBMC
Affected Version From: Linux, Windows
Affected Version To: Tested: Win xp sp2 eng
Patch Exists: YES
Related CWE: N/A
CPE: o:xbmc:xbmc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Xbmc get tag from file name request remote buffer overflow 8.10
This exploit happens when parsing and overly long id3 tag to the web server. It is possible to overwrite the exception handlers also so creating a reliable exploit for vista and xps3 shouldn't be to hard. The exploit is triggered by sending a specially crafted request to the web server.
Mitigation:
Filtering of user input should be done to prevent buffer overflows.