Vulnerability Description
Stack-based buffer overflow in the media library in BS.Global BS.Player 2.51 build 1022, 2.41 build 1003, and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long ID3 tag in a .MP3 file. NOTE: some of these details are obtained from third party information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bsplayer | Bs.Player | 2.41 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/38221Vendor Advisory
- http://www.packetstormsecurity.org/1003-advisories/bsplayerml-overflow.txt
- http://www.securityfocus.com/bid/38568Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4932.phpExploit
- http://secunia.com/advisories/38221Vendor Advisory
- http://www.packetstormsecurity.org/1003-advisories/bsplayerml-overflow.txt
- http://www.securityfocus.com/bid/38568Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4932.phpExploit
FAQ
What is CVE-2010-2009?
CVE-2010-2009 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the media library in BS.Global BS.Player 2.51 build 1022, 2.41 build 1003, and possibly other versions allows user-assisted remote attackers to execute arbitrary code vi...
How severe is CVE-2010-2009?
CVE-2010-2009 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2009?
Check the references section above for vendor advisories and patch information. Affected products include: Bsplayer Bs.Player.