Intrusion Prevention

Ston3d.Player.Command.Injection

Description

This indicates an attack attempt against a command-inject vulnerability in Ston3d Player.
The vulnerability is caused by an error when the vulnerable software handles a malicious lua script. It allows a remote attacker to execute arbitrary code via sending a crafted .stk file.

Affected Products

Win32
S3DPlayer Web v1.6.0.0
S3DPlayer StandAlone v1.6.2.4
S3DPlayer StandAlone v1.7.0.1
MacOS
S3DPlayer Web v1.6.0.0
S3DPlayer StandAlone v1.6.2.4
Linux
S3DPlayer StandAlone v1.6.2.4

Impact

System Compromise

Recommended Actions

Block S3DPlayer traffic.

CVE References

CVE-2009-1792