PT-2009-4280 · Sonic Spot · Sonic Spot Audioactive Player

His0K4

·

Publicado

2009-05-29

·

Atualizado

2017-09-29

·

CVE-2009-1815

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sonic Spot Audioactive Player version 1.93b
Description: The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string in a playlist file. This can be demonstrated by a long .mp3 URL in a .m3u file.
Recommendations: For Sonic Spot Audioactive Player version 1.93b, consider avoiding the use of long strings in playlist files until a patch is available. As a temporary workaround, restrict the length of URLs in .m3u files to prevent potential exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1815

Produtos afetados

Sonic Spot Audioactive Player