PT-2009-2866 · Vuplayer · Vuplayer
Skd
·
Published
2009-01-20
·
Updated
2022-04-22
·
CVE-2009-0182
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VUPlayer versions 2.49 and earlier
Description
The issue allows user-assisted attackers to execute arbitrary code via a long URL in a
File line in a .pls file. This can be demonstrated by an http URL on a File1 line.Recommendations
For VUPlayer versions 2.49 and earlier, avoid using long URLs in
.pls files until a fix is available.
As a temporary workaround, consider restricting the use of .pls files or limiting the length of URLs in File lines to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vuplayer