ArcSoft MMS Composer Multiple Vulnerabilities
BID:19451
CVE-2006-4131 | CVE-2006-4132 |Info
ArcSoft MMS Composer Multiple Vulnerabilities
| Bugtraq ID: | 19451 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2006 12:00AM |
| Updated: | Jan 04 2007 06:26PM |
| Credit: | Collin R. Mulliner and Giovanni Vigna are credited with discovering these vulnerabilities. |
| Vulnerable: |
ArcSoft Composer 2.0 .13 ArcSoft Composer 1.5.5 6 |
| Not Vulnerable: | |
Discussion
ArcSoft MMS Composer Multiple Vulnerabilities
ArcSoft MMS Composer is affected by multiple vulnerabilities, including buffer-overflow and denial-of-service issues.
Successful exploits can allow remote attackers to cause denial-of-service conditions and to execute arbitrary machine code in the context of the user running the application.
ArcSoft MMS Composer is affected by multiple vulnerabilities, including buffer-overflow and denial-of-service issues.
Successful exploits can allow remote attackers to cause denial-of-service conditions and to execute arbitrary machine code in the context of the user running the application.
Exploit / POC
ArcSoft MMS Composer Multiple Vulnerabilities
An attacker can exploit these issues by crafting a malicious MMS message and submitting it to a victim user.
The following exploit code is available:
An attacker can exploit these issues by crafting a malicious MMS message and submitting it to a victim user.
The following exploit code is available:
Solution / Fix
ArcSoft MMS Composer Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
ArcSoft MMS Composer Multiple Vulnerabilities
References:
References:
- ArcSoft Homepage (ArcSoft)
- PocketPC Security Research (Collin Mulliner)