PT-2006-6890 · Quintessential · Quintessential Player
Greg Linares
·
Published
2006-12-04
·
Updated
2017-10-19
·
CVE-2006-6261
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Quintessential Player versions 4.50.1.82 and earlier
Description
The issue allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted files, including M3u, M3u-8, or PLS files with long values in specific fields such as
NumberofEntries, Length, Filename, or Title.Recommendations
For versions 4.50.1.82 and earlier, consider avoiding the use of crafted M3u, M3u-8, or PLS files until a patch is available. As a temporary workaround, restrict the handling of files with long values in the
NumberofEntries, Length, Filename, or Title fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quintessential Player