search menu icon-carat-right cmu-wordmark

CERT Coordination Center

VUPlayer malformed playlist buffer overflow

Vulnerability Note VU#311192

Original Release Date: 2007-09-06 | Last Revised: 2007-09-06

Overview

VUPlayer fails to properly handle malformed playlists. This vulnerability may allow a remote attacker to execute arbitrary code.

Description

VUPlayer is a freeware audio player for the Microsoft Windows platform. It can play various types of media files, such as MP3s. A Playlist (.PLS or .M3U) file is a text file that contains links to other media files to play. VUPlayer supports the use of playlist files.

VUPlayer fails to properly handle malformed playlists allowing a stack-based buffer overflow to occur.

Note that working exploit code is publicly available for this vulnerability.

Impact

A remote unauthenticated attacker may be able to execute arbitrary code by convincing a user to open a specially crafted playlist. This can be achieved by creating a specially crafted web page or other HTML document that may launch VUPlayer without any user interaction.

Solution

We are unaware of a solution to this problem. Until a solution becomes available the following workarounds are strongly encouraged:

Do not open playlist files from untrusted sources

Do not open untrusted playlist files (.PLS or .M3U) with VUPlayer.


Do Not Follow Unsolicited Links

In order to convince users to visit their sites, attackers often use URL encoding, IP address variations, long URLs, intentional misspellings, and other techniques to create misleading links. Do not click on unsolicited links received in email, instant messages, web forums, or internet relay chat (IRC) channels. Type URLs directly into the browser to avoid these misleading links. While these are generally good security practices, following these behaviors will not prevent exploitation of this vulnerability in all cases.

Vendor Information

311192
 

VUPlayer Affected

Updated:  December 04, 2006

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported by Greg Linares.

This document was written by Jeff Gennari.

Other Information

CVE IDs: CVE-2006-6251
Severity Metric: 15.94
Date Public: 2006-12-01
Date First Published: 2007-09-06
Date Last Updated: 2007-09-06 21:51 UTC
Document Revision: 16

Sponsored by CISA.