This application requires Javascript for optimal performance.

Ston3d.Player.Command.Injection

Release Date

Jun 25, 2009

Severity

high

Impact

System Compromise

Description

This indicates an attack attempt against a command-inject vulnerability in Ston3d Player.

The vulnerability is caused by an error when the vulnerable software handles a malicious lua script. It allows a remote attacker to execute arbitrary code via sending a crafted .stk file.

Affected Products

Win32
S3DPlayer Web v1.6.0.0
S3DPlayer StandAlone v1.6.2.4
S3DPlayer StandAlone v1.7.0.1

MacOS
S3DPlayer Web v1.6.0.0
S3DPlayer StandAlone v1.6.2.4

Linux
S3DPlayer StandAlone v1.6.2.4

Recommended Actions

Block S3DPlayer traffic.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-1792

Reference/s

http://www.securityfocus.com/bid/35105 (BugTraq)

Reference: VID-17464