PT-2010-1671 · Ultraplayer · Ultraplayer Media Player

Sarbot511

·

Published

2010-05-10

·

Updated

2017-09-19

·

CVE-2009-4863

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UltraPlayer Media Player version 2.112
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved by providing a long string in a .usk file.
Recommendations For UltraPlayer Media Player version 2.112, update to a newer version that contains a fix for this issue. If no specific fix is provided for version 2.112, consider avoiding the use of .usk files until the issue is resolved. As a temporary workaround, consider restricting access to files that could potentially trigger the buffer overflow.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4863

Affected Products

Ultraplayer Media Player