Microsoft DirectShow MIDI Filetype Buffer Overflow Vulnerability
BID:8262
Info
Microsoft DirectShow MIDI Filetype Buffer Overflow Vulnerability
| Bugtraq ID: | 8262 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0346 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to eEye Digital Security. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT 4.0 SP6a Microsoft DirectX 9.0 a Microsoft DirectX 8.1 b Microsoft DirectX 8.1 a Microsoft DirectX 8.1 Microsoft DirectX 8.0 a Microsoft DirectX 8.0 Microsoft DirectX 7.1 Microsoft DirectX 7.0 a Microsoft DirectX 7.0 Microsoft DirectX 6.1 Microsoft DirectX 5.2 |
| Not Vulnerable: | |
Discussion
Microsoft DirectShow MIDI Filetype Buffer Overflow Vulnerability
Microsoft DirectX is vulnerable to two buffer overflows in the routine used to handle MIDI files. These vulnerabilities may allow attackers to construct a specially malformed MIDI file that when executed, overruns an internal buffer and potentially executes arbitrary code.
Microsoft DirectX is vulnerable to two buffer overflows in the routine used to handle MIDI files. These vulnerabilities may allow attackers to construct a specially malformed MIDI file that when executed, overruns an internal buffer and potentially executes arbitrary code.
Exploit / POC
Microsoft DirectShow MIDI Filetype Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft DirectShow MIDI Filetype Buffer Overflow Vulnerability
Solution:
Microsoft has released fixes for this issue.
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft DirectX 7.0 a
Microsoft DirectX 7.0
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6a
Microsoft DirectX 9.0 a
Microsoft Windows NT 4.0 SP6a
Microsoft DirectX 8.1
Microsoft DirectX 5.2
Microsoft DirectX 6.1
Solution:
Microsoft has released fixes for this issue.
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Q819696i.EXE
Fix for Microsoft Windows NT 4.0 Terminal Server Edition with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=14290AD7-EE7D -4736-8322-BCA4CBD7D7C5&displaylang=en
Microsoft DirectX 7.0 a
-
Microsoft dxwebsetup.exe
All Windows Versions except Windows NT 4.0
http://microsoft.com/downloads/details.aspx?FamilyId=141D5F9E-07C1-462 A-BAEF-5EAB5C851CF5&displaylang=en
Microsoft DirectX 7.0
-
Microsoft dxwebsetup.exe
All Windows Versions except Windows NT 4.0
http://microsoft.com/downloads/details.aspx?FamilyId=141D5F9E-07C1-462 A-BAEF-5EAB5C851CF5&displaylang=en
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q819696i.EXE
Fix for Microsoft Windows NT 4.0 with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=B42C5BCB-6D36 -437D-A07E-053B72B1C652&displaylang=en
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q819696i.EXE
Fix for Microsoft Windows NT 4.0 with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=B42C5BCB-6D36 -437D-A07E-053B72B1C652&displaylang=en
Microsoft DirectX 9.0 a
-
Microsoft DirectX9-KB819696-x86-ENU.exe
Fix for DirectX 9.0 and DirectX 9.0a for all Windows versions except Windows NT 4.0.
http://www.microsoft.com/downloads/details.aspx?FamilyId=22F990CB-E9F9 -4670-8B4F-AC4F6F66C3A2&displaylang=en -
Microsoft dxwebsetup.exe
All Windows Versions except Windows NT 4.0
http://microsoft.com/downloads/details.aspx?FamilyId=141D5F9E-07C1-462 A-BAEF-5EAB5C851CF5&displaylang=en
Microsoft Windows NT 4.0 SP6a
-
Microsoft Q819696i.EXE
Fix for Microsoft Windows NT 4.0 with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=B42C5BCB-6D36 -437D-A07E-053B72B1C652&displaylang=en
Microsoft DirectX 8.1
-
Microsoft WindowsServer2003-KB819696-x86-ENU.exe
Microsoft DirectX 8.1 on Windows Server 2003 32-bit Edition
http://microsoft.com/downloads/details.aspx?FamilyId=A5156FF8-1812-4DB 4-9175-BF9CA370279D&displaylang=en -
Microsoft dxwebsetup.exe
All Windows Versions except Windows NT 4.0
http://microsoft.com/downloads/details.aspx?FamilyId=141D5F9E-07C1-462 A-BAEF-5EAB5C851CF5&displaylang=en -
Microsoft Q819696_WXP_SP2_ia64_ENU.exe
Microsoft DirectX 8.1 on Windows XP 64-bit Edition SP1
http://www.microsoft.com/downloads/details.aspx?FamilyId=8F23F7AF-5317 -4502-8B17-7C1A2139EBDC&displaylang=en
Microsoft DirectX 5.2
-
Microsoft dxwebsetup.exe
All Windows Versions except Windows NT 4.0
http://microsoft.com/downloads/details.aspx?FamilyId=141D5F9E-07C1-462 A-BAEF-5EAB5C851CF5&displaylang=en
Microsoft DirectX 6.1
-
Microsoft dxwebsetup.exe
All Windows Versions except Windows NT 4.0
http://microsoft.com/downloads/details.aspx?FamilyId=141D5F9E-07C1-462 A-BAEF-5EAB5C851CF5&displaylang=en
References
Microsoft DirectShow MIDI Filetype Buffer Overflow Vulnerability
References:
References:
- CERT Advisory CA-2003-18 Integer Overflows in Microsoft Windows DirectX MIDI Lib (CERT)
- Microsoft Security Bulletin MS03-030 (Microsoft)
- Windows MIDI Decoder (QUARTZ.DLL) Heap Corruption (eEye Digital Security)
- Workaround for stopping MS2003-030 exploitation via HTML? ("Johnson, Jeff FOR:EX"
)