Kakao · Potplayer · CVE-2018-16797
**Name of the Vulnerable Software and Affected Versions**
PotPlayer version 1.7.8556
**Description**
A heap-based buffer overflow issue exists, allowing remote attackers to execute arbitrary code via a .wav file with large `BytesPerSec` and `SamplesPerSec` values, and a small `Data Chunk Size` value.
**Recommendations**
For version 1.7.8556, consider avoiding the use of .wav files with large `BytesPerSec` and `SamplesPerSec` values, and a small `Data Chunk Size` value, until a patch is available.