PT-2006-6890 · Quintessential · Quintessential Player
Greg Linares
·
Publicado
2006-12-04
·
Atualizado
2017-10-19
·
CVE-2006-6261
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Quintessential Player versions 4.50.1.82 and earlier
Description
The issue allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted files, including M3u, M3u-8, or PLS files with long values in specific fields such as
NumberofEntries, Length, Filename, or Title.Recommendations
For versions 4.50.1.82 and earlier, consider avoiding the use of crafted M3u, M3u-8, or PLS files until a patch is available. As a temporary workaround, restrict the handling of files with long values in the
NumberofEntries, Length, Filename, or Title fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Quintessential Player