Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulnerability
BID:29578
Info
Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 29578 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1444 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2008 12:00AM |
| Updated: | Jul 30 2008 03:47PM |
| Credit: | An Anonymous Researcher working with Tipping Point and the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Self-Service WVADS 0 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Self-Service CCXML 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self Service VoiceXML 0 Nortel Networks Multimedia Comm MCS5100 Nortel Networks Media Processing Server Nortel Networks ENSM - Enterprise NMS 10.5 Nortel Networks ENSM - Enterprise NMS 10.4 Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Express Nortel Networks Contact Center - TAPI Server 0 Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager 9.0 Nortel Networks Centrex IP Client Manager 11.0 Nortel Networks Centrex IP Client Manager 10.0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Nortel Networks CallPilot 1002rp Microsoft DirectX 8.1 Microsoft DirectX 7.0 a Microsoft DirectX 7.0 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulnerability
Microsoft DirectX is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. The vulnerability occurs when handling malformed SAMI files.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the user running the application that uses DirectX. Failed exploit attempts will result in a denial-of-service condition.
NOTE: Supported editions of Windows Server 2008 are not affected if installed using the Server Core installation option.
Microsoft DirectX is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. The vulnerability occurs when handling malformed SAMI files.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the user running the application that uses DirectX. Failed exploit attempts will result in a denial-of-service condition.
NOTE: Supported editions of Windows Server 2008 are not affected if installed using the Server Core installation option.
Exploit / POC
Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulnerability
Solution:
Microsoft has released an advisory along with fixes. Please see the references for details.
Microsoft DirectX 8.1
Microsoft DirectX 7.0
Solution:
Microsoft has released an advisory along with fixes. Please see the references for details.
Microsoft DirectX 8.1
-
Microsoft Security Update for DirectX 8 for Windows 2000 (KB951698)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c6a28d45-13cf -48c4-8f89-3417d552e90b
Microsoft DirectX 7.0
-
Microsoft Security Update for Windows 2000 (KB951698)
http://www.microsoft.com/downloads/details.aspx?FamilyId=65640123-a9e4 -455c-a51a-9df28bd2d412
References
Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulnerability
References:
References:
- Microsoft DirectX Homepage (Microsoft)
- Microsoft DirectX SAMI File Format Name Parsing Stack Overflow Vulnerability (Zero Day Initiative)
- SAMI Is My Hero: MS08-033 Disassembled (SecureWorks)
- 2008008897 Nortel Response to Microsoft Security Bulletin MS08-033 (Nortel Networks)
- Avaya ASA-2008-235 MS08-033 Vulnerabilities in DirectX Could Allow Remote Code E (Avaya)
- Centrex IP Client Manager (CICM) response to Microsoft June security bulletin (Nortel Networks)
- Microsoft Security Bulletin MS08-033 �?? Critical (Microsoft)