Mini.Stream.PLS.Buffer.Overflow

Last Updated DateFeb 09, 2010
Release DateJan 19, 2010
SeverityHigh
ImpactSecurity Bypass: Remote attackers can bypass security checking of vulnerable systems.
DescriptionThis indicates an attack attempt against a buffer overflow vulnerability in
Mini_stream.
The vulnerability is caused by an error when the vulnerable software handles
a malicious PLS file. It allows a remote attacker to execute arbitrary code via sending a crafted web page.
Affected ProductsMini-Stream 3.0.1.1
Recommended ActionsUpgrade to the latest version, available from the website.
http://www.mini-stream.com/download.htm
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1325
Reference/shttp://www.securityfocus.com/bid/34494 (BugTraq)
http://www.exploit-db.com/exploits/10745
Reference: VID-18083