republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Media Player Classic AVI File Processing Buffer Overflow
Search Topic:
Uniqs:
285
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Should I be seeing this much activity? »
« Mumbai Installing Keyloggers  
AuthorAll Replies


gkweb

join:2003-06-09
76800

Media Player Classic AVI File Processing Buffer Overflow

quote:
TITLE:
Media Player Classic AVI File Processing Buffer Overflow

SECUNIA ADVISORY ID:
SA26806

VERIFY ADVISORY:
»secunia.com/advisories/26806/

CRITICAL:
Highly critical

IMPACT:
System access

WHERE:
>From remote

SOFTWARE:
Media Player Classic 6.x
»secunia.com/product/14824/

DESCRIPTION:
Code Audit Labs has discovered a vulnerability in Media Player
Classic, which can be exploited by malicious people to compromise a
vulnerable system.

The vulnerability is caused due to an input validation error when
processing .AVI files and can be exploited to cause a buffer overflow
via a .AVI file with a specially crafted "indx" chunk.

Successful exploitation allows execution of arbitrary code.

The vulnerability is confirmed in version 6.4.9.0. Other versions may
also be affected.

SOLUTION:
Do not open untrusted .AVI files.

PROVIDED AND/OR DISCOVERED BY:
Code Audit Labs

ORIGINAL ADVISORY:
»www.vulnhunt.com/advisories/CAL-···ties.txt

AVI files are very common, and there is no fix for now.

Regards,
gkweb.
--
Firewall tester : »www.firewallleaktester.com

*member of ASAP : Alliance of Security Analysis Professionals*


jansson_mark
Markus Jansson
Premium
join:2001-08-05
Finland

Again MPC vulnerability, and they havent even bothered to answer to my previous post on sourceforge about their last vulnerability. I guess its time to say byebye to MPC too...
--
My computer security & privacy related homepage »www.markusjansson.net
Use HushTools or GnuPG/PGP to encrypt any email before sending it to me to protect our privacy.


gkweb

join:2003-06-09
76800

Right now, it seems that even Microsoft Windows Media Player 11.x is more secure :
»secunia.com/product/11280/?task=advisories

1 advisory, 0 unpacthed.

Kind of surprising.

Regards,
gkweb.
--
Firewall tester : »www.firewallleaktester.com

*member of ASAP : Alliance of Security Analysis Professionals*
Forums » Up and Running » Security » SecurityShould I be seeing this much activity? »
« Mumbai Installing Keyloggers  


Sunday, 06-Dec 01:04:23 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [122] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· [Newsgroups] Newzleech down? [Filesharing Software]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· [Unlock] TUTORIAL: VONAGE WRTP54G/RTP300 WITH 5.01.04 [VOIP Tech Chat]