First published: Fri Sep 02 2011(Updated: )
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
KMPlayer | =3.0.0.1441 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2594 is classified as a high severity vulnerability due to its potential for remote code execution.
The best way to mitigate CVE-2011-2594 is to update to the latest version of KMPlayer that addresses this vulnerability.
CVE-2011-2594 can be exploited by attackers using specially crafted playlist files containing overly long Title fields.
CVE-2011-2594 specifically affects KMPlayer version 3.0.0.1441 and potentially earlier versions.
Temporary workarounds for CVE-2011-2594 include disabling the use of playlist files until a patch is applied.