Vulnerability Description
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pandora | Kmplayer | <= 4.2.2.15 |
Related Weaknesses (CWE)
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30113Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30113Third Party Advisory
FAQ
What is CVE-2018-5200?
CVE-2018-5200 is a vulnerability with a CVSS score of 7.8 (HIGH). KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than t...
How severe is CVE-2018-5200?
CVE-2018-5200 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5200?
Check the references section above for vendor advisories and patch information. Affected products include: Pandora Kmplayer.