CVE-2009-1068
BS.Player <=2.34 Build 980 - Stack-based Buffer Overflow via Long Hostname in .bsl Playlist File
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-1068. PoCs published by Nine:Situations:Group, His0k4.
AI-analyzed exploit summary This exploit targets a local buffer overflow vulnerability in BS.Player <= 2.34 Build 980 via a malformed .bsl playlist file. It leverages SEH overwrites and includes shellcode to execute arbitrary commands (e.g., calc.exe).
Description
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long hostname in a .bsl playlist file.
Exploits (2)
This exploit targets a local buffer overflow vulnerability in BS.Player <= 2.34 Build 980 via a malformed .bsl playlist file. It leverages SEH overwrites and includes shellcode to execute arbitrary commands (e.g., calc.exe).
This exploit targets a SEH overwrite vulnerability in Bs.Player 2.34 via a crafted .bsl file. It uses a known SEH address from oldskin.dll and includes a Metasploit-generated calc.exe payload.