SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9133

An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.

MEDIUM 5.5EPSS 1.88%

Does this matter?

Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.

Description

When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
1.88% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-190, CWE-191
Affected
kmplayer/kmplayer · fedoraproject/fedora
Source
vuln@krcert.or.kr

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.