PT-2007-7312 · Prosoft · Rosoft Media Player
Juan Pablo Lopez Yacubian
·
Published
2007-12-20
·
Updated
2018-10-15
·
CVE-2007-6478
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Rosoft Media Player versions 4.1.7 through 4.1.8
Rosoft Media Player versions prior to 4.1.7
Description
The issue allows remote attackers to execute arbitrary code or cause a denial of service via a long string in a .M3U file.
Recommendations
For Rosoft Media Player versions 4.1.7 and 4.1.8, update to a version that fixes this issue.
For Rosoft Media Player versions prior to 4.1.7, update to a version that fixes this issue.
As a temporary workaround, consider avoiding the use of .M3U files with long strings until a patch is available.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rosoft Media Player