Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/7695 | exploit vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48170 | vdb entry third party advisory |
http://securityreason.com/securityalert/4923 | third party advisory exploit |
http://packetstormsecurity.com/files/165489/VUPlayer-2.49-Buffer-Overflow.html | exploit vdb entry third party advisory |