Vulnerability record · CVE-2009-2485 · published 16 July 2009
CVE-2009-2485: HT-MP3Player .ht3 file stack buffer overflow
Tingan · Ht Mp3player
HT-MP3Player 1.0 contains a stack-based buffer overflow (CWE-119) triggered by a long string in a .ht3 file. Opening a crafted file can overwrite stack memory and allow arbitrary code execution. The flaw is remotely reachable because the malicious file can be delivered to the victim.
Description
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityPublic exploit code exists and the flaw allows remote code execution, but the product is old and the record lacks patch and vendor details.
What it is
HT-MP3Player 1.0 contains a stack-based buffer overflow (CWE-119) triggered by a long string in a .ht3 file. Opening a crafted file can overwrite stack memory and allow arbitrary code execution. The flaw is remotely reachable because the malicious file can be delivered to the victim.
Impact
An attacker who gets a victim to open a crafted .ht3 file can execute arbitrary code in the context of the player process. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
Reached by supplying a malicious .ht3 file to the application; the CVSS vector AV:N/AC:M/Au:N indicates network delivery with no authentication, but medium complexity and likely user interaction to open the file.
Exploitation
No CISA KEV listing and no ransomware association. EPSS is 0.58099 (99th percentile), and the only references are two duplicate Exploit-DB entries, indicating public exploit code exists.
What to do
- Upgrade or replace HT-MP3Player 1.0; no fixed version is identified in this record, so treat the product as unsupported if no patch exists.
- Block or strip .ht3 files at email and web gateways until the player is removed or patched.
- Remove HT-MP3Player from endpoints where it is not required, or restrict its file associations.
- Warn users not to open .ht3 files from untrusted sources.
Detection
- Monitor for HT-MP3Player process crashes or abnormal child processes spawned from the player.
- Scan email and web proxy logs for .ht3 file transfers.
- Hunt for .ht3 files on endpoints and inspect them for oversized strings.
- Alert on Exploit-DB 9034 signatures or related payload patterns in network or host telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-2485 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2485), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.