CVE-2010-20042
Severity CVSS v4.0:
HIGH
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
20/08/2025
Last modified:
22/08/2025
Description
Xion Audio Player versions prior to 1.0.126 are vulnerable to a Unicode-based stack buffer overflow triggered by opening a specially crafted .m3u playlist file. The file contains an overly long string that overwrites the Structured Exception Handler (SEH) chain, allowing an attacker to hijack execution flow and run arbitrary code.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/xion_m3u_sehbof.rb
- https://www.exploit-db.com/exploits/14517
- https://www.exploit-db.com/exploits/14633
- https://www.exploit-db.com/exploits/15598
- https://www.exploit-db.com/exploits/16653
- https://www.r2.com.au/page/products/download/xion-audio-player/
- https://www.vulncheck.com/advisories/xion-audio-player-unicode-stack-buffer-overflow



