Vulnerabilities > CVE-2004-0964
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 11 |
Exploit-Db
description Zinf Audio Player 2.2.1 (.pls) Universal Seh Overwrite Exploit. CVE-2004-0964. Local exploit for windows platform id EDB-ID:8267 last seen 2016-02-01 modified 2009-03-23 published 2009-03-23 reporter His0k4 source https://www.exploit-db.com/download/8267/ title Zinf Audio Player 2.2.1 - .pls Universal Seh Overwrite Exploit description Zinf Audio Player 2.2.1 (PLS File) Local Buffer Overflow Exploit (univ). CVE-2004-0964. Local exploit for windows platform id EDB-ID:7888 last seen 2016-02-01 modified 2009-01-28 published 2009-01-28 reporter Houssamix source https://www.exploit-db.com/download/7888/ title Zinf Audio Player 2.2.1 PLS File Local Buffer Overflow Exploit univ description Zinf Audio Player 2.2.1 - (.pls) Buffer Overflow Vulnerability (DEP BYPASS). CVE-2004-0964. Local exploit for windows platform id EDB-ID:17600 last seen 2016-02-02 modified 2011-08-03 published 2011-08-03 reporter C4SS!0 and h1ch4m source https://www.exploit-db.com/download/17600/ title Zinf Audio Player 2.2.1 - .pls Buffer Overflow Vulnerability DEP BYPASS description Zinf 2.2.1 Local Buffer Overflow Exploit. CVE-2004-0964. Local exploit for windows platform id EDB-ID:559 last seen 2016-01-31 modified 2004-09-28 published 2004-09-28 reporter Delikon source https://www.exploit-db.com/download/559/ title Zinf 2.2.1 - Local Buffer Overflow Exploit description Zinf Audio Player 2.2.1 (PLS File) Stack Buffer Overflow. CVE-2004-0964. Local exploit for windows platform id EDB-ID:16688 last seen 2016-02-02 modified 2010-11-24 published 2010-11-24 reporter metasploit source https://www.exploit-db.com/download/16688/ title Zinf Audio Player 2.2.1 PLS File Stack Buffer Overflow description Zinf Audio Player 2.2.1 (PLS File) Stack Overflow PoC. CVE-2004-0964. Dos exploit for windows platform id EDB-ID:7887 last seen 2016-02-01 modified 2009-01-27 published 2009-01-27 reporter Hakxer source https://www.exploit-db.com/download/7887/ title Zinf Audio Player 2.2.1 PLS File Stack Overflow PoC
Metasploit
description | This module exploits a stack-based buffer overflow in the Zinf Audio Player 2.2.1. An attacker must send the file to victim and the victim must open the file. Alternatively it may be possible to execute code remotely via an embedded PLS file within a browser, when the PLS extension is registered to Zinf. This functionality has not been tested in this module. |
id | MSF:EXPLOIT/WINDOWS/FILEFORMAT/ZINFAUDIOPLAYER221_PLS |
last seen | 2020-01-12 |
modified | 2017-11-08 |
published | 2009-04-29 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0964 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/fileformat/zinfaudioplayer221_pls.rb |
title | Zinf Audio Player 2.2.1 (PLS File) Stack Buffer Overflow |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-587.NASL |
description | Luigi Auriemma discovered a buffer overflow condition in the playlist module of freeamp which could lead to arbitrary code execution. Recent versions of freeamp were renamed into zinf. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15685 |
published | 2004-11-10 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15685 |
title | Debian DSA-587-1 : freeamp - buffer overflow |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/83051/zinfaudioplayer221_pls.rb.txt |
id | PACKETSTORM:83051 |
last seen | 2016-12-05 |
published | 2009-11-26 |
reporter | patrick |
source | https://packetstormsecurity.com/files/83051/Zinf-Audio-Player-2.2.1-PLS-File-Stack-Overflow..html |
title | Zinf Audio Player 2.2.1 (PLS File) Stack Overflow. |
References
- http://marc.info/?l=bugtraq&m=109608092609200&w=2
- http://marc.info/?l=bugtraq&m=109608092609200&w=2
- http://marc.info/?l=bugtraq&m=109638486728548&w=2
- http://marc.info/?l=bugtraq&m=109638486728548&w=2
- http://secunia.com/advisories/12656
- http://secunia.com/advisories/12656
- http://securityreason.com/securityalert/8341
- http://securityreason.com/securityalert/8341
- http://www.debian.org/security/2004/dsa-587
- http://www.debian.org/security/2004/dsa-587
- http://www.securityfocus.com/bid/11248
- http://www.securityfocus.com/bid/11248
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17491
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17491