|
|
|
|
|
| Microsoft Windows Indeo Codec Multiple Vulnerabilities |
|
Search
|
|
|
|
Security News
|
|
 |
Mathew J. Schwartz, InformationWeek |
2010-08-27 14:11:17 |
Email and peer-to-peer networks also rank as significant venues for malware attacks, which have increased slightly in the U.S. but declined in Europe, according to Panda Security. |
|
 |
Hugo Jean, Heptacube Inc. |
2010-08-24 14:51:53 |
The motivation behind the $7.68 billion deal is unclear, but Intel says it wants to integrate computer security into its hardware. |
|
|
IT Directory
|
| Wiseleap Solutions Inc. | |
|
Founded in 2005, Wiseleap Solutions Inc.'s mission consists in providing companies with the information necessary to make cri [...]
|
| IT Ration Consulting Inc. | |
|
IT-Ration Consulting inc has been a NetSuite Partner since 2005 and helps your enterprise grow by aligning your Information T [...]
|
| HumanWare | |
|
Empowering People
Focused on enhancing the lives of people with visual and learning disabilities, HumanWare provide [...]
|
|
|
|
By Secunia
|
|
|
2009-12-09 09:53:38
|
Description:
Multiple vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
1) An error in the Indeo41 codec when processing a specific size within the "movi" record of a IV41 stream can be exploited to cause a heap-based buffer overflow.
2) An error in the Indeo41 codec when decompressing a video stream can be exploited to cause a stack-based buffer overflow.
3) An unspecified error in the Indeo codec can be exploited to corrupt memory.
4) Other vulnerabilities also exist and are caused due to unspecified errors in the Indeo codec and can be exploited to corrupt memory by tricking a user into viewing specially crafted media content.
Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
Solution:
Microsoft has issued an update that reduces the attack surface by preventing loading of Indeo content from the Internet zone in general and via Internet Explorer and Windows Media Player. However, other third-party applications may still use it to render media content and thus present attack vectors.
Provided and/or discovered by:
1) Reported by an anonymous person via ZDI.
2) Reported by an anonymous person via ZDI.
3) Bing Liu, Fortinet's FortiGuard Labs.
4) The vendor credits Paul Byrne of NGS Software, VeriSign iDefense Labs, and Dave Lenoe of Adobe.
Changelog:
2009-12-09: Added additional information provided by ZDI.
Original Advisory:
Microsoft:
http://www.microsoft.com/technet/security/advisory/954157.mspx
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-089/
http://www.zerodayinitiative.com/advisories/ZDI-09-090/
No CVE references.
|
|
Tags |
Indeo InternetExplorer Microsoft WindowsMediaPlayer |