PT-2014-3424 · Allplayer · Allplayer

Metacom

·

Published

2014-10-30

·

Updated

2016-12-31

·

CVE-2013-7409

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ALLPlayer versions 5.6.2 through 5.8.1
Description The issue is caused by a buffer overflow that can be triggered by a long string in a .m3u (playlist) file, potentially allowing remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.
Recommendations For versions 5.6.2 through 5.8.1, update to a version that fixes the buffer overflow issue to prevent potential code execution and denial of service attacks.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7409

Affected Products

Allplayer