PT-2007-7436 · Coolplayer · Coolplayer

Published

2007-12-31

·

Updated

2018-10-15

·

CVE-2007-6609

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CoolPlayer versions 217 and earlier
Description The issue is related to multiple stack-based buffer overflows in the CPLI ReadTag OGG function. This allows user-assisted remote attackers to execute arbitrary code via a long cTag or cValue field in an OGG Vorbis file.
Recommendations For CoolPlayer versions 217 and earlier, update to a version later than 217 to resolve the issue. As a temporary workaround, consider avoiding the use of OGG Vorbis files with long cTag or cValue fields until a patch is available. Restrict access to potentially malicious OGG Vorbis files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6609

Affected Products

Coolplayer