Vulnerabilities > CVE-2006-6251 - Buffer Overflow vulnerability in VUPlayer M3U UNC Name

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
vuplayer
exploit available
metasploit

Summary

Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.

Vulnerable Configurations

Part Description Count
Application
Vuplayer
1

Exploit-Db

  • descriptionVUPlayer M3U Buffer Overflow. CVE-2006-6251. Local exploit for windows platform
    idEDB-ID:16617
    last seen2016-02-02
    modified2010-11-11
    published2010-11-11
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16617/
    titleVUPlayer - M3U Buffer Overflow
  • descriptionVUPlayer. CVE-2006-6251. Remote exploit for windows platform
    fileexploits/windows/remote/2870.rb
    idEDB-ID:2870
    last seen2016-01-31
    modified2006-11-30
    platformwindows
    port
    published2006-11-30
    reporterGreg Linares
    sourcehttps://www.exploit-db.com/download/2870/
    titleVUPlayer <= 2.44 - .M3U UNC Name Buffer Overflow Exploit meta
    typeremote
  • descriptionVUPlayer. CVE-2006-6251. Local exploit for windows platform
    fileexploits/windows/local/2872.c
    idEDB-ID:2872
    last seen2016-01-31
    modified2006-11-30
    platformwindows
    port
    published2006-11-30
    reporterExpanders
    sourcehttps://www.exploit-db.com/download/2872/
    titleVUPlayer <= 2.44 - .M3U UNC Name Buffer Overflow Exploit c
    typelocal

Metasploit

descriptionThis module exploits a stack over flow in VUPlayer <= 2.49. When the application is used to open a specially crafted m3u file, an buffer is overwritten allowing for the execution of arbitrary code.
idMSF:EXPLOIT/WINDOWS/FILEFORMAT/VUPLAYER_M3U
last seen2020-03-18
modified2020-01-15
published2009-10-16
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6251
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/fileformat/vuplayer_m3u.rb
titleVUPlayer M3U Buffer Overflow

Packetstorm