Subtitle Processor 7.7.1 .m3u SEH Unicode Buffer Overflow
Vulnerability Description
Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-10025
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Brandon Murphy
References
- https://www.fortiguard.com/encyclopedia/ips/26849
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/subtitle_processor_m3u_bof.rb
- https://www.exploit-db.com/exploits/17217
- https://www.exploit-db.com/exploits/17225
- https://sourceforge.net/projects/subtitleproc/
- https://www.vulncheck.com/advisories/subtitle-processor-m3u-seh-unicode-buffer-overflow
Affected Vendor
Subtitle Processor
View all reports →