I disclosured a crash in potplayer last year : https://seclists.org/fulldisclosure/2021/Mar/76 And I found a new one this year, this time is a mid file. Again I contacted Korea Internet & Security Agency(first-team@xxxxxxxxxxxx), they shared report to the onwer of the potplayer, Kakao Corp as they said. But I did not get any update after about half a year. So this is a 0day. I cannot debug or get any useful information about the crash bacause the program was packed. You can get POC in attachment.
Attachment:
potplayer.7z
Description: Binary data
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/