CVE-2011-2594: Buffer Overflow
Published Sep 2, 2011
·Updated
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.
Affected Software
1 affected component
KMPlayer KMPlayer=3.0.0.1441
Event History
Sep 2, 2011
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2594?
CVE-2011-2594 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2011-2594?
The best way to mitigate CVE-2011-2594 is to update to the latest version of KMPlayer that addresses this vulnerability.
3
What types of attacks can exploit CVE-2011-2594?
CVE-2011-2594 can be exploited by attackers using specially crafted playlist files containing overly long Title fields.
4
What versions of KMPlayer are affected by CVE-2011-2594?
CVE-2011-2594 specifically affects KMPlayer version 3.0.0.1441 and potentially earlier versions.
5
Are there any workarounds for CVE-2011-2594?
Temporary workarounds for CVE-2011-2594 include disabling the use of playlist files until a patch is applied.