oss-sec mailing list archives
CVE request for Media Player Classic
From: Andreas Lindh <addelindh () gmail com>
Date: Wed, 10 Feb 2016 14:41:16 +0100
Hi list, CVE-assign, On the 14th of November 2015, Media Player Classic - Home Cinema (MPC-HC) disabled the preview function in the MPC-HC Web UI in version 1.7.10, as this function could be abused to steal private images from the machine running MPC-HC with the Wen UI enabled. See https://mpc-hc.org/changelog/ for the MPC-HC changelog, and http://haxx.ml/post/125666329821/abusing-the-mpc-hc-webui-to-steal-private-pictures for more details on the issue and practical exploitation of it. The main issue here is that the Web UI does not have any authentication, something which (besides the already mentioned issue) enables an attacker on the same network to start media files on the MPC-HC running on the affect machine. Could a CVE be assigned for this please? Cheers, Andreas
Current thread:
- CVE request for Media Player Classic Andreas Lindh (Feb 10)