|
Microsoft Windows DirectShow AVI Handling Vulnerability
|
|
Secunia Advisory:
|
SA17160
|
|
|
Release Date:
|
2005-10-11
|
|
Last Update:
|
2006-02-10
|
|
Popularity:
|
17,500 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows XP Embedded Microsoft Windows XP Home Edition Microsoft Windows XP Professional
|
| | Software: | Microsoft DirectX 7.x Microsoft DirectX 8.x Microsoft DirectX 9.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
| | CVE reference: | CVE-2005-2128
|
|
Description: eEye Digital Security has been reported a vulnerability in Microsoft Windows DirectShow, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a validation error in QUARTZ.DLL when decoding AVI movie files. This can be exploited to write a null byte to an arbitrary memory location e.g. the header of the heap block.
Successful exploitation allows arbitrary code execution, but requires that the user open a malicious AVI file with specially crafted value in the length field of the "strn" element.
Solution: Apply patches.
Microsoft DirectX 7.0 on Microsoft Windows 2000 (requires Service Pack 4):
http://www.microsoft.com/downloads/de...=2feffe6c-6c1c-42d9-b15e-f8f8d9c0e60e
Microsoft DirectX 8.1 on Microsoft Windows XP (requires Service Pack 1 or 2):
http://www.microsoft.com/downloads/de...=2636cfce-49ea-4d06-80ba-21a84f3658a5
Microsoft DirectX 8.1 on Microsoft Windows XP Professional x64 Edition:
http://www.microsoft.com/downloads/de...=ef614cdc-1db5-4b5c-8440-714941799a9f
Microsoft DirectX 8.1 on Microsoft Windows Server 2003 (with and without Service Pack 1):
http://www.microsoft.com/downloads/de...=66f44766-3741-4c83-aa5f-1b3498131dd9
Microsoft DirectX 8.1 on Microsoft Windows Server 2003 (Itanium) (with and without Service Pack 1):
http://www.microsoft.com/downloads/de...=7f8342a0-2462-46d3-9e40-262f72db68a6
Microsoft DirectX 8.1 on Microsoft Windows Server 2003 x64 Edition:
http://www.microsoft.com/downloads/de...=76c3815c-a966-49eb-825f-1b8454c09bbf
Microsoft DirectX 8.0, 8.0a, 8.1, 8.1a, 8.1b, and 8.2 on Windows 2000 (requires Service Pack 4):
http://www.microsoft.com/downloads/de...=FEDC7212-27B8-4993-9965-53E9298DB386
Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c on Windows 2000 (requires Service Pack 4):
http://www.microsoft.com/downloads/de...=1853AD1F-92C8-4C2B-8F52-9B2FC8DBF769
Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c on Windows XP (requires Service Pack 1):
http://www.microsoft.com/downloads/de...=36FBED29-E264-4BC7-AB48-2CC4A59ACAA1
Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c on Windows Server 2003:
http://www.microsoft.com/downloads/de...=6083BA2D-4F1A-4900-8F7D-A32CB41CB5FA
Microsoft Windows XP Embedded (with SP2):
http://www.microsoft.com/downloads/de...=e7b6d199-7607-44a8-96fd-5a2386427bd9
Microsoft Windows XP Embedded (with SP1):
http://www.microsoft.com/downloads/de...=af116ff1-9347-40d5-b03c-c2c758c652ba
Provided and/or discovered by: Fang Xing, eEye Digital Security.
Changelog: 2005-10-12: Added information from eEye Digital Security. Updated "Description", "Original Advisory", "Other References", and credit sections.
2005-11-21: Added patch information for Windows XP Embedded.
2006-02-10: Added patch information for Windows XP Embedded with SP1.
Original Advisory: MS05-050 (KB904706):
http://www.microsoft.com/technet/security/Bulletin/MS05-050.mspx
eEye Digital Security:
http://www.eeye.com/html/research/advisories/AD20051011a.html
Other References: US-CERT VU#995220
http://www.kb.cert.org/vuls/id/995220
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
10th Oct, 2008
|
New advisories:
|
15 |
|
New vulnerabilities:
|
83 |
|
Updated advisories:
|
41 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|