CVE-2009-3429

Pirate Radio Destiny Media Player 1.61 - Stack-Based Buffer Overflow via .pls Playlist File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2009-3429. PoCs published by Metasploit, ThE g0bL!N, Encrypt3d.M!nd, including Metasploit module exploits/windows/fileformat/destinymediaplayer16.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in Destiny Media Player 1.61 via a maliciously crafted M3U playlist file. It leverages a JMP ESP instruction to execute arbitrary shellcode, achieving remote code execution when the victim opens the file.

Description

Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.

Exploits (7)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16684

This exploit targets a stack-based buffer overflow in Destiny Media Player 1.61 via a maliciously crafted M3U playlist file. It leverages a JMP ESP instruction to execute arbitrary shellcode, achieving remote code execution when the victim opens the file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Destiny Media Player 1.61
No auth needed
Prerequisites: Victim must open the malicious M3U file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ThE g0bL!N · perllocalwindows
https://www.exploit-db.com/exploits/9321

This exploit targets a buffer overflow vulnerability in Destiny Media Player 1.61 via a malformed .pls file. It leverages SEH overwrite with a jump to shellcode that spawns calc.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Destiny Media Player 1.61
No auth needed
Prerequisites: Victim must open the malicious .pls file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Encrypt3d.M!nd · perllocalwindows
https://www.exploit-db.com/exploits/7654

This exploit targets a local buffer overflow in Destiny Media Player 1.61 via a maliciously crafted .lst file. It uses a SEH-based overflow with a calc.exe payload, tested on Windows XP SP3.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Destiny Media Player 1.61
No auth needed
Prerequisites: Victim must import the malicious .lst file into Destiny Media Player
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/7651

This exploit targets a local stack overflow vulnerability in Destiny Media Player 1.61 via a maliciously crafted .m3u file. It overwrites the EIP with a call to ESP from kernel32.dll and executes a calc.exe payload using Metasploit-generated shellcode.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Destiny Media Player 1.61
No auth needed
Prerequisites: Victim must open the malicious .m3u file in Destiny Media Player 1.61
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Encrypt3d.M!nd · perldoswindows
https://www.exploit-db.com/exploits/7652

This is a buffer overflow PoC for Destiny Media Player that writes a malicious .lst file with a controlled EIP overwrite. It demonstrates a crash condition but lacks a functional payload.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Destiny Media Player (version unspecified)
No auth needed
Prerequisites: Victim must open the malicious .lst file in Destiny Media Player
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by aBo MoHaMeD · perldoswindows
https://www.exploit-db.com/exploits/7649

This Perl script generates a malicious .m3u file containing a buffer overflow payload (31185 'A' characters) targeting Destiny Media Player 1.61.0. The PoC triggers a local stack overflow when the file is opened, potentially allowing arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Destiny Media Player 1.61.0
No auth needed
Prerequisites: Victim must open the malicious .m3u file in Destiny Media Player
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/destinymediaplayer16.rb

This Metasploit module exploits a stack-based buffer overflow in Destiny Media Player 1.61 via a maliciously crafted M3U playlist file. It leverages a JMP ESP instruction to redirect execution to the payload, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Destiny Media Player 1.61
No auth needed
Prerequisites: Victim must open the malicious M3U file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9321

Scores

EPSS 0.7195
EPSS Percentile 98.8%

Details

CWE
CWE-119
Status published
Products (1)
pirateradio/destiny_media_player 1.61
Published Sep 25, 2009
Tracked Since Feb 18, 2026