HTTP: CoolPlayer Playlist File Handling Buffer Overflow

This signature detects attempts to exploit a known vulnerability in CoolPlayer. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

CoolPlayer is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data. The issue occurs when handling specially crafted M3U files. Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.

Affected Products

Coolplayer coolplayer

References

BugTraq: 30418

CVE: CVE-2008-3408

Short Name
HTTP:STC:DL:COOLPLAYER-PLAYLIST
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2008-3408 CoolPlayer File Handling Overflow Playlist bid:30418
Release Date
10/11/2010
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Coolplayer

CVSS Score

6.8

Found a potential security threat?