PT-2007-7365 · Inmatrix · Zoom Player

Luigi Auriemma

·

Published

2007-12-27

·

Updated

2018-10-15

·

CVE-2007-6533

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zoom Player versions 6.00 beta 2 and earlier
Description The issue allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file. This occurs because of a buffer overflow in Unicode handling when generating an error message.
Recommendations For Zoom Player versions 6.00 beta 2 and earlier, update to a version later than 6.00 beta 2 to resolve the issue. As a temporary workaround, consider avoiding the use of crafted ZPL files and be cautious when clicking on HTTP links to PLS files.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6533

Affected Products

Zoom Player