Mailing List Archive

TotalPlayer 3.0 .m3u crash
Software: TotalPlayer 3.0
Link: http://www.totalplayer.net/total_player_free.exe

Vulnerability:
The software fails when we open a file with .m3u extension with a large content of bytes. The program will close unexpectedly.

POC:

http://emilianonunez.em.funpic.de/default.rar


Regards,

David G.M. --> Trancek
Re: TotalPlayer 3.0 .m3u crash [ In reply to ]
Total Player in reality is the recompiling of the CoolPlayer source code
available on the official website http://coolplayer.sf.net with the
"CoolPlayer" string substituited by "Total Player" (but with the same
skin, that's why it shows the CoolPlayer name).

Other than being in full GPL violation its installer contains a spyware
too (totalplayer.exe "seems" safe).

And yes, also CoolPlayer 217 is vulnerable to this stack buffer-overflow
vulnerability.

The problem is visible in the CPL_AddPrefixedFile function in
CPI_Playlist.c, memcpy + strcpy on cFullPath which is 260 bytes long.


---
Luigi Auriemma
http://aluigi.org
Re: TotalPlayer 3.0 .m3u crash [ In reply to ]
Ehmmm sorry for the double post, the problem is still the same
which is already known from one year or two as stated in the following
advisory of Mehdi Oudad and Kevin Fernandez of zone-h.fr:

http://www.zone-h.fr/fr/advisories/read/id=1548/
http://seclists.org/fulldisclosure/2006/Dec/0254.html


---
Luigi Auriemma
http://aluigi.org
Re: Re: TotalPlayer 3.0 .m3u crash [ In reply to ]
It's true, I don't know the coolplayer but I see and it's the same software, so I searched any change in the virtual machine and I saw this:

C:\Archivos de programa\OneStepSearch

If a person downloaded and executed this software you have to erase this, now I'm seeing the malware but it's seems that it isn't any danger.

Sorry, I download a lot of software for fuzz and I don't review this details.

Thanks Luigi ;)

PD:Sorry for my english jeje
Re: Re: Re: TotalPlayer 3.0 .m3u crash [ In reply to ]
To eliminate the malware completely, you should read this information:

http://ca.com/es/securityadvisor/pest/pest.aspx?id=453118839

Sorry for the double topic