When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.
References
Link | Resource |
---|---|
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=34991 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4D55BLGBNWNIMNI5N57WDPAFQCUIM6XX/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VT5HBIKH64YRZFFAPXGOTHIQJHSTQJF7/ | Mailing List Third Party Advisory |
Information
Published : 2019-04-09 11:29
Updated : 2021-11-03 12:49
NVD link : CVE-2019-9133
Mitre link : CVE-2019-9133
JSON object : View
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)
Products Affected
microsoft
- windows
fedoraproject
- fedora
kmplayer
- kmplayer