Ston3d.Player.Command.Injection

Release DateJun 25, 2009
SeverityHigh
ImpactSystem Compromise
DescriptionThis indicates an attack attempt against a command-inject vulnerability in Ston3d Player.

The vulnerability is caused by an error when the vulnerable software handles a malicious lua script. It allows a remote attacker to execute arbitrary code via sending a crafted .stk file.
Affected ProductsWin32
S3DPlayer Web v1.6.0.0
S3DPlayer StandAlone v1.6.2.4
S3DPlayer StandAlone v1.7.0.1

MacOS
S3DPlayer Web v1.6.0.0
S3DPlayer StandAlone v1.6.2.4

Linux
S3DPlayer StandAlone v1.6.2.4
Recommended ActionsBlock S3DPlayer traffic.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1792
Reference/shttp://www.securityfocus.com/bid/35105 (BugTraq)
Reference: VID-17464