When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesnt check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kmplayer | Kmplayer | * | 2018.12.24.14 (including) |