Description
HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.
Problem types
Product status
Credits
Dino Covotsos - Telspace Systems
References
www.exploit-db.com/exploits/46279 (ExploitDB-46279)
www.html5videoplayer.net/download.html (Official Product Homepage)
www.vulncheck.com/...eo-player-local-buffer-overflow-non-seh (VulnCheck Advisory: HTML5 Video Player 1.2.5 Local Buffer Overflow Non-SEH)