PT-2009-3950 · Coolplayer · Coolplayer+ Portable

Gold_M

+1

·

Published

2009-04-27

·

Updated

2017-09-29

·

CVE-2009-1449

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CoolPlayer+ Portable version 2.19.1
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved via a skin file, specifically skin.ini, that contains a large PlaylistSkin parameter.
Recommendations For CoolPlayer+ Portable version 2.19.1, consider avoiding the use of skin files with large PlaylistSkin parameters until a fix is available. As a temporary workaround, restrict the use of skin files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1449

Affected Products

Coolplayer+ Portable