This application requires Javascript for optimal performance.

GOM.Player.ASX.Playlist.Buffer.Overflow

Release Date

Mar 12, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer-overflow vulnerability in GOM Player.

The vulnerability is caused by an error when the vulnerable software handles a malicious .ASX playlist. It allows a remote attacker to execute arbitrary code via sending a crafted .ASX file.

Affected Products

GOM Player 2.0.12.3375

Recommended Actions

Update to version 2.1.1.3399.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-0707

Reference: VID-14070