45939vdb entry
http://osvdb.org/45939 CVE-2007-4941
KMPlayer 2.9.3.1214 - Multiple Remote Denial of Service Vulnerabilities
Record summary
CVE-2007-4941 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.
Description
KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKMPlayer 2.9.3.1214 - Multiple Remote Denial of Service VulnerabilitiesExploitDB exploitby Code Audit LabsNot analyzed1 file
References
73144Third-party advisory
http://securityreason.com/securityalert/3144 20070912 CAL-20070912-1 Multiple vendor produce handling AVI file vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/479222/100/0/threaded 25651vdb entry
http://www.securityfocus.com/bid/25651 vulnhunt.com
http://www.vulnhunt.com/advisories/CAL-20070912-1_Multiple_vendor_produce_handling_AVI_file_vulnerabilities.txt kmplayer-avi-dos(36585)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/36585 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4941