Security Advisory

CVE-2019-9133

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-09 17:33:27
Last updated 2024-08-04 21:38:46
Assigner krcert
CVSS score 7.8
State PUBLISHED

Description

When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.