Rosoft Media Player Track List Files Stack-Based Buffer Overflow Vulnerability
BID:26920
Info
Rosoft Media Player Track List Files Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 26920 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6478 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Juan Pablo Lopez Yacubian discovered this issue. |
| Vulnerable: |
Rosoft Engineering Rosoft Media Player 4.4.4 Rosoft Engineering Rosoft Media Player 4.2.1 Rosoft Engineering Rosoft Media Player 4.1.8 Rosoft Engineering Rosoft Media Player 4.1.7 |
| Not Vulnerable: | |
Discussion
Rosoft Media Player Track List Files Stack-Based Buffer Overflow Vulnerability
Rosoft Media Player is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successful exploits allow remote attackers to execute arbitrary code in the context of the user running the application. Failed attacks will cause denial-of-service conditions.
Rosoft Media Player 4.1.7, 4.1.8, and 4.2.1 are vulnerable; other versions may also be affected.
NOTE: This BID originally covered this issue as a denial-of-service vulnerability; further information shows that the issue is more severe.
UPDATE (January 18, 2010): Rosoft Media Player 4.4.4 is also vulnerable to this issue when opening crafted '.m3u' playlist files.
Rosoft Media Player is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successful exploits allow remote attackers to execute arbitrary code in the context of the user running the application. Failed attacks will cause denial-of-service conditions.
Rosoft Media Player 4.1.7, 4.1.8, and 4.2.1 are vulnerable; other versions may also be affected.
NOTE: This BID originally covered this issue as a denial-of-service vulnerability; further information shows that the issue is more severe.
UPDATE (January 18, 2010): Rosoft Media Player 4.4.4 is also vulnerable to this issue when opening crafted '.m3u' playlist files.
Exploit / POC
Rosoft Media Player Track List Files Stack-Based Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious file using the affected application.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious file using the affected application.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Rosoft Media Player Track List Files Stack-Based Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Rosoft Media Player Track List Files Stack-Based Buffer Overflow Vulnerability
References:
References:
- Rosoft Engineering Homepage (Rosoft Engineering)
- Re: Rosoft Media Player 4.1.8 RML Stack Based Buffer Overflow ([email protected])
- Rosoft Media Player 4.1.8 Buffer Overflow ( .M3U) ([email protected])
- Rosoft Media Player 4.1.7 crash ([email protected])
- Rosoft Media Player 4.1.8 RML Stack Based Buffer Overflow ([email protected])