Release date:
Updated on:
Affected Systems:
UMPlayer 0.98.
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-3494
UMPlayer is a fully functional multimedia player.
UMPlayer 0.98 and other versions load the (wintab32.dll) Library in an insecure manner. By enticing users to open some files shared by remote WebDAV or SMB, remote attackers can exploit this vulnerability to load arbitrary libraries.
<* Source: kaveh ghaemmaghami
Link: http://secunia.com/advisories/53484/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
UMPlayer
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.umplayer.com/