Microsoft DirectX RLE Compressed Targa Image File Heap Overflow Overflow Vulnerability
BID:24963
Info
Microsoft DirectX RLE Compressed Targa Image File Heap Overflow Overflow Vulnerability
| Bugtraq ID: | 24963 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4183 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2007 12:00AM |
| Updated: | Jul 19 2007 05:16PM |
| Credit: | Rubén Santamarta is credited for the discovery of this vulnerability. |
| Vulnerable: |
Microsoft DirectX SDK February 2006 Microsoft DirectX End User Runtimes February 2006 |
| Not Vulnerable: |
Microsoft DirectX SDK June 2007 Microsoft DirectX End User Runtimes June 2007 |
Discussion
Microsoft DirectX RLE Compressed Targa Image File Heap Overflow Overflow Vulnerability
A heap-based buffer-overflow vulnerability occurs in the Microsoft Windows DirectX component. This issue is related to the processing of compressed Targa image files. The specific vulnerability occurs because of the way these files are opened.
A successful exploit will permit attackers to execute arbitrary code in the context of the user who opens a malicious RLE Targa image file.
An attacker can exploit this issue through any means that will allow the attacker to deliver a malicious Targa file to a victim user. In web-based attack scenarios, exploits could occur automatically if the malicious page can cause the file to be loaded automatically by Windows Media Player. Other attack vectors such as email or instant messaging may require the victim user to manually open the malicious Targa file.
A heap-based buffer-overflow vulnerability occurs in the Microsoft Windows DirectX component. This issue is related to the processing of compressed Targa image files. The specific vulnerability occurs because of the way these files are opened.
A successful exploit will permit attackers to execute arbitrary code in the context of the user who opens a malicious RLE Targa image file.
An attacker can exploit this issue through any means that will allow the attacker to deliver a malicious Targa file to a victim user. In web-based attack scenarios, exploits could occur automatically if the malicious page can cause the file to be loaded automatically by Windows Media Player. Other attack vectors such as email or instant messaging may require the victim user to manually open the malicious Targa file.
Exploit / POC
Microsoft DirectX RLE Compressed Targa Image File Heap Overflow Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft DirectX RLE Compressed Targa Image File Heap Overflow Overflow Vulnerability
Solution:
Microsoft has released updates to address this vulnerability in the October 2006 SDK and End-User Runtime releases; please see the reference section for details.
Microsoft DirectX SDK February 2006
Microsoft DirectX End User Runtimes February 2006
Solution:
Microsoft has released updates to address this vulnerability in the October 2006 SDK and End-User Runtime releases; please see the reference section for details.
Microsoft DirectX SDK February 2006
-
Microsoft DirectX End-User Runtime Web Installer
http://www.microsoft.com/downloads/details.aspx?FamilyId=2DA43D38-DB71 -4C1B-BC6A-9B6652CD92A3&displaylang=en
Microsoft DirectX End User Runtimes February 2006
-
Microsoft DirectX End-User Runtime Web Installer
http://www.microsoft.com/downloads/details.aspx?FamilyId=2DA43D38-DB71 -4C1B-BC6A-9B6652CD92A3&displaylang=en
References
Microsoft DirectX RLE Compressed Targa Image File Heap Overflow Overflow Vulnerability
References:
References:
- Microsoft DirectX Homepage (Microsoft)
- [[email protected]: [Reversemode Advisory] Microsoft DirectX RLE Compr (Reversemode
) - iDefense Security Advisory 07.18.07: Microsoft DirectX RLE Compressed Targa Imag (iDefense Labs
)