Vulnerability Note VU#311192
VUPlayer malformed playlist buffer overflow
OverviewVUPlayer fails to properly handle malformed playlists. This vulnerability may allow a remote attacker to execute arbitrary code.
I. DescriptionVUPlayer is a freeware audio player for the Microsoft Windows platform. It can play various types of media files, such as MP3s. A Playlist (.PLS or .M3U) file is a text file that contains links to other media files to play. VUPlayer supports the use of playlist files.
VUPlayer fails to properly handle malformed playlists allowing a stack-based buffer overflow to occur.
Note that working exploit code is publicly available for this vulnerability.
II. ImpactA remote unauthenticated attacker may be able to execute arbitrary code by convincing a user to open a specially crafted playlist. This can be achieved by creating a specially crafted web page or other HTML document that may launch VUPlayer without any user interaction.
III. SolutionWe are unaware of a solution to this problem. Until a solution becomes available the following workarounds are strongly encouraged:
Do not open playlist files from untrusted sources
Do not open untrusted playlist files (.PLS or .M3U) with VUPlayer.
Do Not Follow Unsolicited Links
In order to convince users to visit their sites, attackers often use URL encoding, IP address variations, long URLs, intentional misspellings, and other techniques to create misleading links. Do not click on unsolicited links received in email, instant messages, web forums, or internet relay chat (IRC) channels. Type URLs directly into the browser to avoid these misleading links. While these are generally good security practices, following these behaviors will not prevent exploitation of this vulnerability in all cases.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| VUPlayer | Vulnerable | 4-Dec-2006 |
References
http://www.securityfocus.com/bid/21363
http://www.frsirt.com/english/advisories/2006/4783
http://secunia.com/advisories/23182
http://xforce.iss.net/xforce/xfdb/30629
Credit
This vulnerability was reported by Greg Linares.
This document was written by Jeff Gennari.
Other Information
| Date Public: | 2006-12-01 |
| Date First Published: | 2007-09-06 |
| Date Last Updated: | 2007-09-06 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2006-6251 |
| NVD-ID(s): | CVE-2006-6251 |
| US-CERT Technical Alerts: | |
| Metric: | 15.94 |
| Document Revision: | 16 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|