PT-2010-1369 · A2 · A2 Media Player Pro
Hack4Love
·
Publicado
2010-01-04
·
Atualizado
2017-09-19
·
CVE-2009-4549
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
A2 Media Player Pro version 2.51
Description
The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This can be achieved by providing a long string in either a .m3u or .m3l playlist file.
Recommendations
For version 2.51, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict the handling of .m3u and .m3l playlist files to minimize the risk of exploitation. Avoid using the media player to open files from untrusted sources until the issue is resolved.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
A2 Media Player Pro