PDA

View Full Version : Zoom Player Unicode Buffer Overflow



newsbot
25-12-2007, 03:45 PM
Zoom Player (http://www.inmatrix.com) is "a media player for Windows which supports many formats through external filters". Zoom Player is affected by an unicode buffer-overflow in the function which builds the error messages. The problem can be exploited for example through a malformed ZPL file containing a http link to a file with PLS extension which will force the program to use wsprintf for building the "Unable to play [%s]" error message.

http://www.securiteam.com/windowsntfocus/6B00L1FKKC.html