Search:     Advanced search
server monitoring

3ivx MPEG-4 < 5.0.2 Buffer Overflow

Article ID: 29749
Last updated: 27 Jan, 2009
Views: 487
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

3ivx MPEG-4 < 5.0.2 Buffer Overflow

This script is Copyright (C) 2007-2008 Tenable Network Security, Inc.

FamilyWindows
Plugin ID29749
Bugtraq ID26773
CVE IDCVE-2007-6401
CVE-2007-6402

Description:

Synopsis :

The remote Windows host contains an application that is prone to a
buffer overflow vulnerability.

Description :

The 3ivx MPEG-4 compression suite is installed on the remote host. It
contains an MP4 codec for use with media players such as Windows Media
Player for creating and playing back MPEG-4 / MP4 files.

The version of this codec on the remote host is affected by a buffer
overflow vulnerability. If an attacker can trick a user on the
affected host into opening a specially-crafted MP4 file with a media
player that uses this codec, he may be able to leverage this issue to
execute arbitrary code on the affected host subject to the users
privileges.

See also :

http://www.securityfocus.com/archive/1/484781/30/0/threaded
http://www.securityfocus.com/archive/1/484779/30/0/threaded
http://www.3ivx.com/pr/pr20071213_502.html

Solution :

Upgrade to 3ivx MPEG-4 compression suite version 5.0.2 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
PhatBOT detection     HP Instant Support HPISDataManager.dll ActiveX Control <...