PT-2010-1369 · A2 · A2 Media Player Pro
Hack4Love
·
Published
2010-01-04
·
Updated
2017-09-19
·
CVE-2009-4549
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
A2 Media Player Pro version 2.51
Description
The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This can be achieved by providing a long string in either a .m3u or .m3l playlist file.
Recommendations
For version 2.51, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict the handling of .m3u and .m3l playlist files to minimize the risk of exploitation. Avoid using the media player to open files from untrusted sources until the issue is resolved.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
A2 Media Player Pro