CVE-2010-2004
BS.Global BS.Player 2.51 Build 1022 - Stack-Based Buffer Overflow via Skin Parameter in BSI File
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2010-2004. PoCs published by Dz_attacker, Mert SARICA.
AI-analyzed exploit summary This exploit targets a SEH overflow vulnerability in BS.Player v2.51. It crafts a malicious .bsi file with a payload that triggers a buffer overflow, leading to arbitrary code execution (calc.exe in this case).
Description
Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different vulnerability than CVE-2009-1068.
Exploits (2)
This exploit targets a SEH overflow vulnerability in BS.Player v2.51. It crafts a malicious .bsi file with a payload that triggers a buffer overflow, leading to arbitrary code execution (calc.exe in this case).
This exploit generates a malicious .bsi file for BS.Player v2.51 by overwriting the SEH with a controlled pattern, demonstrating a buffer overflow vulnerability. The PoC creates a file that triggers the crash when opened.