First published: Fri May 21 2010(Updated: )
Stack-based buffer overflow in the media library in BS.Global BS.Player 2.51 build 1022, 2.41 build 1003, and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long ID3 tag in a .MP3 file. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BSPlayer | =2.41 | |
BSPlayer | =2.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2009 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2010-2009, upgrade BS.Player to version 2.52 or later, which addresses the buffer overflow issue.
CVE-2010-2009 allows attackers to execute arbitrary code on the victim's system by crafting malicious .MP3 files with long ID3 tags.
CVE-2010-2009 affects BS.Player versions 2.41 and 2.51, along with potentially other unspecified versions.
Exploitation of CVE-2010-2009 requires user interaction, as the user must open a specially crafted .MP3 file.