Hiya
CoolPlayer is vulnerable to a buffer overflow, caused by improper bounds checking by main_skin_open() function. By creating a specially-crafted skin file containing an overly long bitmap filename and persuading a victim to open the file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
Platforms Affected:
Microsoft Corporation: Windows 95
Microsoft Corporation: Windows 98
Microsoft Corporation: Windows 98 Second Edition
Microsoft Corporation: Windows Me
Microsoft Corporation: Windows XP
Microsoft Corporation: Windows 2000 Any version
Microsoft Corporation: Windows 2003 Any version
Microsoft Corporation: Windows NT 4.0
Open Source Technology Group: CoolPlayer 215 and prior http://xforce.iss.net/xforce/xfdb/30863