oss-sec mailing list archives

CVE request for Media Player Classic


From: Andreas Lindh <addelindh () gmail com>
Date: Wed, 10 Feb 2016 14:41:16 +0100

Hi list, CVE-assign,

On the 14th of November 2015, Media Player Classic - Home Cinema (MPC-HC)
disabled the preview function in the MPC-HC Web UI in version 1.7.10, as
this function could be abused to steal private images from the machine
running MPC-HC with the Wen UI enabled.

See https://mpc-hc.org/changelog/ for the MPC-HC changelog, and
http://haxx.ml/post/125666329821/abusing-the-mpc-hc-webui-to-steal-private-pictures
for more details on the issue and practical exploitation of it.

The main issue here is that the Web UI does not have any authentication,
something which (besides the already mentioned issue) enables an attacker
on the same network to start media files on the MPC-HC running on the
affect machine.

Could a CVE be assigned for this please?

Cheers,
Andreas

Current thread: