PT-2007-7436 · Coolplayer · Coolplayer
Published
2007-12-31
·
Updated
2018-10-15
·
CVE-2007-6609
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CoolPlayer versions 217 and earlier
Description
The issue is related to multiple stack-based buffer overflows in the CPLI ReadTag OGG function. This allows user-assisted remote attackers to execute arbitrary code via a long
cTag or cValue field in an OGG Vorbis file.Recommendations
For CoolPlayer versions 217 and earlier, update to a version later than 217 to resolve the issue. As a temporary workaround, consider avoiding the use of OGG Vorbis files with long
cTag or cValue fields until a patch is available. Restrict access to potentially malicious OGG Vorbis files to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coolplayer