PT-2010-1564 · Mercury · Mercury Audio Player
His0K4
·
Published
2010-03-29
·
Updated
2017-09-19
·
CVE-2009-4755
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mercury Audio Player version 1.21
Description
The issue concerns multiple stack-based buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved by sending a long string in a malformed playlist file, specifically in .b4s or .pls files.
Recommendations
For Mercury Audio Player version 1.21, consider updating to a newer version that addresses this issue, as using malformed playlist files can lead to arbitrary code execution. If no update is available, restrict the use of .b4s and .pls playlist files to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mercury Audio Player