Bugtraq mailing list archives
Re: TotalPlayer 3.0 .m3u crash
From: Luigi Auriemma <aluigi () autistici org>
Date: Thu, 27 Dec 2007 11:27:11 +0100
Total Player in reality is the recompiling of the CoolPlayer source code available on the official website http://coolplayer.sf.net with the "CoolPlayer" string substituited by "Total Player" (but with the same skin, that's why it shows the CoolPlayer name). Other than being in full GPL violation its installer contains a spyware too (totalplayer.exe "seems" safe). And yes, also CoolPlayer 217 is vulnerable to this stack buffer-overflow vulnerability. The problem is visible in the CPL_AddPrefixedFile function in CPI_Playlist.c, memcpy + strcpy on cFullPath which is 260 bytes long. --- Luigi Auriemma http://aluigi.org
Current thread:
- TotalPlayer 3.0 .m3u crash david130490 (Dec 25)
- <Possible follow-ups>
- Re: TotalPlayer 3.0 .m3u crash Luigi Auriemma (Dec 27)
- Re: TotalPlayer 3.0 .m3u crash Luigi Auriemma (Dec 27)
- Re: Re: TotalPlayer 3.0 .m3u crash david130490 (Dec 27)
- Re: Re: Re: TotalPlayer 3.0 .m3u crash david130490 (Dec 27)