Summary
This host is installed with VUPlayer and is prone to Buffer Overflow vulnerability.
Impact
Attackers may leverage this issue by executing arbitrary code in the context of an affected application and can cause denial of service condition.
Impact Level: Application
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
For updates refer to http://www.vuplayer.com/vuplayer.php
Insight
Certain .asx and .pls files fails to perform adequate boundary checks in HREF attribute of a REF element via long .asf file. This can also be exploited by a file composed entirely of 'A' characters.
Affected
VUPlayer version 2.49 (2.4.9.0) and prior on Windows.
Severity
Classification
-
CVE CVE-2009-0174, CVE-2009-0181, CVE-2009-0182 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Asterisk IAX2 Call Number Exhaustion DOS Vulnerability (Linux)
- Foxit Reader Multiple Denial of Service Vulnerabilities - Jun09
- Apple Safari Multiple Vulnerabilities June-09 (Win) - II
- Apple QuickTime Malformed .mov File Buffer Overflow Vulnerability
- Colasoft Capsa Malformed SNMP V1 Packet Remote Denial of Service Vulnerability