SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#311192

VUPlayer malformed playlist buffer overflow

Overview

VUPlayer fails to properly handle malformed playlists. This vulnerability may allow a remote attacker to execute arbitrary code.

I. Description

VUPlayer is a freeware audio player for the Microsoft Windows platform. It can play various types of media files, such as MP3s. A Playlist (.PLS or .M3U) file is a text file that contains links to other media files to play. VUPlayer supports the use of playlist files.

VUPlayer fails to properly handle malformed playlists allowing a stack-based buffer overflow to occur.

Note that working exploit code is publicly available for this vulnerability.

II. Impact

A remote unauthenticated attacker may be able to execute arbitrary code by convincing a user to open a specially crafted playlist. This can be achieved by creating a specially crafted web page or other HTML document that may launch VUPlayer without any user interaction.

III. Solution

We are unaware of a solution to this problem. Until a solution becomes available the following workarounds are strongly encouraged:


Do not open playlist files from untrusted sources

Do not open untrusted playlist files (.PLS or .M3U) with VUPlayer.

Do Not Follow Unsolicited Links

In order to convince users to visit their sites, attackers often use URL encoding, IP address variations, long URLs, intentional misspellings, and other techniques to create misleading links. Do not click on unsolicited links received in email, instant messages, web forums, or internet relay chat (IRC) channels. Type URLs directly into the browser to avoid these misleading links. While these are generally good security practices, following these behaviors will not prevent exploitation of this vulnerability in all cases.

Systems Affected

VendorStatusDate NotifiedDate Updated
VUPlayerVulnerable4-Dec-2006

References


http://www.securityfocus.com/bid/21363
http://www.frsirt.com/english/advisories/2006/4783
http://secunia.com/advisories/23182
http://xforce.iss.net/xforce/xfdb/30629

Credit

This vulnerability was reported by Greg Linares.

This document was written by Jeff Gennari.

Other Information

Date Public:2006-12-01
Date First Published:2007-09-06
Date Last Updated:2007-09-06
CERT Advisory: 
CVE-ID(s):CVE-2006-6251
NVD-ID(s):CVE-2006-6251
US-CERT Technical Alerts: 
Metric:15.94
Document Revision:16

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader