PT-2010-3629 · Ab Team · Bs.Player

Gjoko Krstic

·

Published

2010-05-21

·

Updated

2010-05-24

·

CVE-2010-2009

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BS.Player versions 2.41 build 1003 through 2.51 build 1022
Description A stack-based buffer overflow issue exists in the media library of the affected software, allowing user-assisted remote attackers to execute arbitrary code via a long ID3 tag in a .MP3 file.
Recommendations For versions 2.41 build 1003 through 2.51 build 1022, consider disabling the media library functionality until a patch is available to prevent exploitation. Restrict access to .MP3 files with long ID3 tags to minimize the risk of arbitrary code execution.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2009

Affected Products

Bs.Player