CVE-2009-4841
Roxio CinePlayer 3.2 - Remote Code Execution via DiskType Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4841. PoCs published by snakespc.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Roxio CinePlayer 3.2 via the SonicMediaPlayer.dll ActiveX control. It uses a heap spray technique to achieve remote code execution by overflowing the DiskType method with a crafted buffer.
Description
Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. NOTE: this might overlap CVE-2007-1559.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Roxio CinePlayer 3.2 via the SonicMediaPlayer.dll ActiveX control. It uses a heap spray technique to achieve remote code execution by overflowing the DiskType method with a crafted buffer.