PT-2009-3649 · Ab Team · Bs.Player

His0K4

·

Publicado

2009-03-24

·

Atualizado

2018-10-10

·

CVE-2009-1068

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BS.Player versions 2.32 Build 975 through 2.34 Build 980 and earlier
Description The issue is a stack-based buffer overflow that can be triggered by a long hostname in a .bsl playlist file, potentially allowing remote attackers to cause a denial of service or execute arbitrary code.
Recommendations For versions 2.32 Build 975 through 2.34 Build 980 and earlier, consider avoiding the use of long hostnames in .bsl playlist files until a fix is available. As a temporary workaround, restrict the length of hostnames in .bsl files to prevent potential exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1068

Produtos afetados

Bs.Player