BS.Player 2.57 Buffer Overflow via M3U Playlist Import
Vulnerability Description
BS.Player version 2.57 (build 1051) contains a vulnerability in its playlist import functionality. When processing .m3u files, the application fails to properly validate the length of playlist entries, resulting in a buffer overflow condition. This flaw occurs during parsing of long URLs embedded in the playlist, allowing overwrite of Structured Exception Handler (SEH) records. The vulnerability is triggered upon opening a crafted playlist file and affects the Unicode parsing logic in the Windows client.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-10016
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- C4SS!0 G0M3S
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/bsplayer_m3u.rb
- https://www.exploit-db.com/exploits/15934
- https://www.exploit-db.com/exploits/18375
- http://www.bsplayer.com/
- https://www.vulncheck.com/advisories/bs-player-buffer-overflow-via-m3u-playlist-import
Affected Vendor
BS.Player
View all reports →