3ivx MPEG-4 Multiple Remote Stack Based Buffer Overflow Vulnerabilities
BID:26773
Info
3ivx MPEG-4 Multiple Remote Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26773 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6401 CVE-2007-6402 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2007 12:00AM |
| Updated: | May 07 2015 06:20PM |
| Credit: | SYS 49152 is credited with the discovery of these issues. |
| Vulnerable: |
3ivx 3ivx MPEG-4 5.0.1 |
| Not Vulnerable: |
3ivx 3ivx MPEG-4 5.0.2 |
Discussion
3ivx MPEG-4 Multiple Remote Stack Based Buffer Overflow Vulnerabilities
3ivx MPEG-4 is prone to multiple stack-based buffer-overflow issues because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
3ivx MPEG-4 5.0.1 is vulnerable; other versions may also be affected.
NOTE: This BID originally listed Windows Media Player as vulnerable, but has been updated to reflect the fact that the issues reside in 3ivx MPEG-4.
3ivx MPEG-4 is prone to multiple stack-based buffer-overflow issues because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
3ivx MPEG-4 5.0.1 is vulnerable; other versions may also be affected.
NOTE: This BID originally listed Windows Media Player as vulnerable, but has been updated to reflect the fact that the issues reside in 3ivx MPEG-4.
Exploit / POC
3ivx MPEG-4 Multiple Remote Stack Based Buffer Overflow Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious MP4 file.
The following proof-of-concept code is available:
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious MP4 file.
The following proof-of-concept code is available:
Solution / Fix
3ivx MPEG-4 Multiple Remote Stack Based Buffer Overflow Vulnerabilities
Solution:
The vendor has released 3ivx MPEG-4 5.0.2 to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released 3ivx MPEG-4 5.0.2 to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
References
3ivx MPEG-4 Multiple Remote Stack Based Buffer Overflow Vulnerabilities
References:
References: