CVE-2010-2009
https://notcve.org/view.php?id=CVE-2010-2009
Stack-based buffer overflow in the media library in BS.Global BS.Player 2.51 build 1022, 2.41 build 1003, and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long ID3 tag in a .MP3 file. NOTE: some of these details are obtained from third party information. Desbordamiento de búfer basado en pila en la librería multimedia de BS.Global BS.Player v2.51 build 1022, v2.41 build 1003, y posiblemente otras versiones. Permite a atacantes remotos asistidos por el usuario ejecutar código de su elección a través de un etiqueta extensa ID3 en un fichero .MP3. NOTA: algunos de estos detalles han sido obtenidos de información de terceras partes. • http://secunia.com/advisories/38221 http://www.packetstormsecurity.org/1003-advisories/bsplayerml-overflow.txt http://www.securityfocus.com/bid/38568 http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4932.php • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2010-2004 – BS.Player 2.51 - Overwrite (SEH)
https://notcve.org/view.php?id=CVE-2010-2004
Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different vulnerability than CVE-2009-1068. Desbordamiento de búffer basado en pila de BS.Global BS.Player v2.51 Build 1022 Free y posiblemente otras versiones, permite a atacantes remotos asistidos por el usuario a través del parámetro Skin en la sección Options de un fichero "skins" (.bsi), vulnerabilidad diferente que CVE-2009-1068. • https://www.exploit-db.com/exploits/11146 https://www.exploit-db.com/exploits/11154 http://secunia.com/advisories/38221 http://www.exploit-db.com/exploits/11154 http://www.mertsarica.com/?p=511 http://www.mertsarica.com/codes/bsplayer_seh_overwrite.py http://www.securityfocus.com/bid/37831 http://www.vupen.com/english/advisories/2010/0148 https://exchange.xforce.ibmcloud.com/vulnerabilities/55708 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •