First published: Thu May 20 2010(Updated: )
Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different vulnerability than CVE-2009-1068.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BSPlayer | =2.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2004 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2010-2004, users should update BS.Player to a version that is not affected by this vulnerability.
CVE-2010-2004 is caused by a stack-based buffer overflow that occurs when processing the Skin parameter in skins files.
Exploiting CVE-2010-2004 could allow remote attackers to execute arbitrary code on the affected system.
While CVE-2010-2004 is confirmed to affect BS.Player 2.51, other versions may also be vulnerable.