Release date:
Updated on:
Affected Systems:
PPLive 1.9.21
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47508
PPLive Network TV is a media owned by PPLive. It is the world's largest online TV with the largest installation volume. It supports the "live broadcast + On-Demand" function for massive HD video content.
PPLive has a configuration vulnerability. Remote attackers can exploit this vulnerability to use the client TCP/9415 proxy without authorization.
The proxy server should only listen on 127.0.0.1, but in fact it listens on all interfaces.
<* Source: hinkydink
Link: http://seclists.org/fulldisclosure/2011/Apr/324
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PPLive
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.pplive.com/en/index.html