Vulnerability record · CVE-2013-7409 · published 30 October 2014
CVE-2013-7409: ALLPlayer playlist buffer overflow via long .m3u string
Allplayer · Allplayer
ALLPlayer versions 5.6.2 through 5.8.1 contain a buffer overflow (CWE-119) triggered by a long string in a .m3u playlist file. A remote attacker can crash the application and possibly execute arbitrary code. The flaw matters because playlist files are commonly exchanged and opened by users, giving an unauthenticated remote path to code execution on the victim's machine.
Description
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploits exist and EPSS is very high, but exploitation requires the user to open a malicious playlist and the product is a consumer media player, limiting broad enterprise exposure.
What it is
ALLPlayer versions 5.6.2 through 5.8.1 contain a buffer overflow (CWE-119) triggered by a long string in a .m3u playlist file. A remote attacker can crash the application and possibly execute arbitrary code. The flaw matters because playlist files are commonly exchanged and opened by users, giving an unauthenticated remote path to code execution on the victim's machine.
Impact
An attacker can cause a denial of service (crash) and potentially execute arbitrary code in the context of the user running ALLPlayer. Successful exploitation could lead to full compromise of the user's system.
Attack surface
Reached remotely over the network (CVSS vector AV:N) by supplying a crafted .m3u file; no authentication is required (Au:N). Exploitation depends on the victim opening the malicious playlist, so some form of user interaction is needed despite the vector not encoding it.
Exploitation
Multiple public exploit references exist (Packet Storm and Exploit-DB entries tagged Exploit), and EPSS is high at 0.67936 (99.3rd percentile), indicating elevated likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Upgrade ALLPlayer to a version later than 5.8.1 if the vendor provides one; the record does not name a fixed version, so verify with the vendor.
- If no fixed version exists, remove or restrict ALLPlayer on endpoints that handle untrusted media files.
- Block or quarantine .m3u files from untrusted sources at email and web gateways.
- Train users not to open playlist files received from unknown or unexpected senders.
- Apply application allowlisting or endpoint controls to limit execution of media players handling untrusted content.
Detection
- Monitor for ALLPlayer process crashes and abnormal termination events on endpoints.
- Hunt for .m3u files with unusually long lines or oversized playlist entries arriving via email or downloads.
- Review endpoint telemetry for ALLPlayer spawning child processes or making unexpected network connections after opening a playlist.
- Search for known exploit file names or hashes associated with the public Exploit-DB and Packet Storm references.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-7409 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-7409), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.