exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Nemesis Player (NSP) Local Denial Of Service

Nemesis Player (NSP) Local Denial Of Service
Posted Jan 5, 2010
Authored by Rehan Ahmed | Site rewterz.com

Nemesis Player (NSP) version 2.0 and 1.1 Beta suffer from a local denial of service vulnerability.

tags | advisory, denial of service, local
SHA-256 | 34e3203485a0554043b5299f37eae4ab898276e5a4ac823a39381bea40f83fb6

Nemesis Player (NSP) Local Denial Of Service

Change Mirror Download
========================================================
Rewterz 05/01/2010

- Nemesis Player (NSP) Local Denial of Service (DoS) Vulnerability -

1) Affected Software

* NSP 2.0
* NSP 1.1 Beta


========================================================
2) Severity

Rating: High
Impact: Denial of Service
Where: Local


========================================================
3) Vendor's Description of Software

"The Nemesis Player (NSP) is much more than any other media player.
It allows you to watch your video files collection like any player
but also enables you to emulate a "DVD menu" for your videos.

Nsp can be broken down into 3 parts: Scene Editing, Project Settings
and the player itself."

Product Link:
https://www.nsplayer.org


========================================================
4) Description of Vulnerability

Rewterz has discovered vulnerability in Nemesis Player (NSP). This
vulnerability could lead to Denial of Service with the privileges of
the current process or user and cause system to stop responding.

This vulnerability exists in the handling of Nsp project file. We chose
not to provide detailed information about the location of the
vulnerability and how to reproduce it because the author hasn't
confirmed this vulnerability. We can pass a long argument into the Nsp
project file. There is no checking of the length of these inputs.
Depending on the input, this will cause DoS condition.

We have confirmed the ability to execute our own code.


========================================================
5) Credits

Discovered by Rehan Ahmed, Rewterz.


========================================================
6) About Rewterz

Rewterz is a boutique Information Security company, committed to
consistently providing world class professional security services.
Our strategy revolves around the need to provide round-the-clock
quality information security services and solutions to our customers.
We maintain this standard through our highly skilled and professional
team, and custom-designed, customer-centric services and products.

https://www.rewterz.com


Complete list of vulnerability advisories published by Rewterz:

https://rewterz.com/securityadvisories.php


========================================================
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close