CoolPlayer 'CPLI_ReadTag_OGG()' Buffer Overflow Vulnerability
BID:27061
Info
CoolPlayer 'CPLI_ReadTag_OGG()' Buffer Overflow Vulnerability
| Bugtraq ID: | 27061 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6609 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 28 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Luigi Auriemma discovered this vulnerability. |
| Vulnerable: |
CoolPlayer CoolPlayer 217 |
| Not Vulnerable: | |
Discussion
CoolPlayer 'CPLI_ReadTag_OGG()' Buffer Overflow Vulnerability
CoolPlayer is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
The issue occurs when handling specially crafted OGG files.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
CoolPlayer 217 is vulnerable; other versions may also be affected.
CoolPlayer is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
The issue occurs when handling specially crafted OGG files.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
CoolPlayer 217 is vulnerable; other versions may also be affected.
Exploit / POC
CoolPlayer 'CPLI_ReadTag_OGG()' Buffer Overflow Vulnerability
The following proof-of-concept code is available:
vorbiscomment -t cTag=AAA_2500_A's_AAA -a input.ogg output.ogg
The following proof-of-concept code is available:
vorbiscomment -t cTag=AAA_2500_A's_AAA -a input.ogg output.ogg
Solution / Fix
CoolPlayer 'CPLI_ReadTag_OGG()' Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CoolPlayer 'CPLI_ReadTag_OGG()' Buffer Overflow Vulnerability
References:
References:
- CoolPlayer Web Site (CoolPlayer)
- Buffer-overflow in CoolPlayer 217 (Luigi Auriemma
)