From: houjingyi <houjingyi647 () gmail com>
Date: Sun, 27 Nov 2022 18:52:13 +0800
I disclosured a crash in potplayer last year : https://seclists.org/fulldisclosure/2021/Mar/76 And I found a new one this year, this time is a mid file. Again I contacted Korea Internet & Security Agency(first-team () krcert or kr), they shared report to the onwer of the potplayer, Kakao Corp as they said. But I did not get any update after about half a year. So this is a 0day. I cannot debug or get any useful information about the crash bacause the program was packed. You can get POC in attachment.
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
- crashing potplayer again houjingyi (Nov 29)