PT-2010-1564 · Mercury · Mercury Audio Player

His0K4

·

Published

2010-03-29

·

Updated

2017-09-19

·

CVE-2009-4755

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mercury Audio Player version 1.21
Description The issue concerns multiple stack-based buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved by sending a long string in a malformed playlist file, specifically in .b4s or .pls files.
Recommendations For Mercury Audio Player version 1.21, consider updating to a newer version that addresses this issue, as using malformed playlist files can lead to arbitrary code execution. If no update is available, restrict the use of .b4s and .pls playlist files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4755

Affected Products

Mercury Audio Player