Vulnerability Name: | CVE-2019-9133 (CCN-159290) | ||||||||||||
Assigned: | 2019-04-05 | ||||||||||||
Published: | 2019-04-05 | ||||||||||||
Updated: | 2021-11-03 | ||||||||||||
Summary: | When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-191 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-9133 Source: CCN Type: KMPlayer Web site KMPlayer Source: XF Type: UNKNOWN kmplayer-cve20199133-underflow(159290) Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2019-32a2bf945e Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2019-9b1da08d62 Source: CCN Type: KrCERT Security Advisory KMPlayer Subtitles parser integer underflow vulnerability Source: MISC Type: Third Party Advisory https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=34991 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||
BACK |