PT-2010-1649 · Sonic+1 · Sonicmediaplayer Activex Control+1

Snakespc

+1

·

Published

2010-05-05

·

Updated

2017-09-19

·

CVE-2009-4841

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Roxio CinePlayer version 3.2
Description A heap-based buffer overflow issue exists in the SonicMediaPlayer ActiveX control, which can be exploited by providing a long argument to the DiskType method, allowing remote attackers to execute arbitrary code.
Recommendations For Roxio CinePlayer version 3.2, consider disabling the SonicMediaPlayer ActiveX control until a patch is available to prevent potential exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4841

Affected Products

Roxio Cineplayer
Sonicmediaplayer Activex Control