This application requires Javascript for optimal performance.

Multiple.Player.S3m.Buffer.Overflow

Release Date

May 20, 2011

Severity

high

Impact

System compromise.

Description

This indicates an attack attempt against a buffer overflow vulnerability in MJM Core Player.

The vulnerability is caused by an error when the vulnerable software handles a malicious .s3m file. It allows a remote attacker to execute arbitrary code via sending a crafted .s3m file.

Affected Products

MJM Core Player 2011

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.
Do not open untrusted .s3m files.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1574

Reference/s

http://osvdb.org/show/osvdb/72101
http://www.securityfocus.com/bid/47248 (BugTraq)
http://www.corelan.be/advisories.php?id=CORELAN-11-003
http://www.corelan.be/advisories.php?id=CORELAN-11-004
http://www.securityfocus.com/bid/47665 (BugTraq)

Reference: VID-26850