CVE-2018-5200: KMPlayer Heap Overflow Vulnerability
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5200?
CVE-2018-5200 is classified as a high severity vulnerability due to its potential for exploitation and memory corruption.
How do I fix CVE-2018-5200?
To fix CVE-2018-5200, users should upgrade KMPlayer to version 4.2.2.16 or later.
What types of attacks can CVE-2018-5200 enable?
CVE-2018-5200 can enable remote code execution attacks if successfully exploited with a malicious FLV file.
Which versions of KMPlayer are affected by CVE-2018-5200?
KMPlayer versions 4.2.2.15 and earlier are affected by CVE-2018-5200.
What causes the vulnerability in CVE-2018-5200?
CVE-2018-5200 is caused by a heap-based buffer overflow due to improper handling of frame data in FLV files.