Heap-based buffer overflow in Xunlei Thunder - CVE-2007-6144

 

Heap-based buffer overflow in Xunlei Thunder - CVE-2007-6144

Published: December 10, 2016 / Updated: February 28, 2017


Vulnerability identifier: #VU1246
CSH Severity: Critical
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2007-6144
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to boundary error in PPlayer.XPPlayer.1 ActiveX control when handling long strings passed via FlvPlayerUrl property value. A remote attacker can create a specially crafted web page, trick the victim into visiting it, cause a heap-based buffer overflow and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability results in compromise of vulnerable system.

Note: this vulnerability was being actively exploited.


Affected software

Xunlei Thunder

How to mitigate CVE-2007-6144

Cybersecurity Help is not aware of any official solution to address this vulnerability. It is recommended to permanently remove the affected software from your system.


External References

Related Security Bulletins