PT-2010-3629 · Ab Team · Bs.Player
Gjoko Krstic
·
Published
2010-05-21
·
Updated
2010-05-24
·
CVE-2010-2009
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BS.Player versions 2.41 build 1003 through 2.51 build 1022
Description
A stack-based buffer overflow issue exists in the media library of the affected software, allowing user-assisted remote attackers to execute arbitrary code via a long ID3 tag in a .MP3 file.
Recommendations
For versions 2.41 build 1003 through 2.51 build 1022, consider disabling the media library functionality until a patch is available to prevent exploitation. Restrict access to .MP3 files with long ID3 tags to minimize the risk of arbitrary code execution.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bs.Player