Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a) NumberofEntries, (b) Length (aka Length1), (c) Filename (aka File1), (d) Title (aka Title1) field, or other unspecified fields.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_2000 | Microsoft | * | * |
Windows_95 | Microsoft | * | * |
Windows_98 | Microsoft | * | * |
Windows_me | Microsoft | * | * |
Windows_nt | Microsoft | 4.0 (including) | 4.0 (including) |
Windows_xp | Microsoft | * | * |