PT-2007-1819 · Intervideo+2 · Windvd+2

Publicado

2007-03-21

·

Atualizado

2018-10-16

·

CVE-2007-0348

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: InterActual Player version 2.60.12.0717 Roxio CinePlayer version 3.2 WinDVD version 7.0.27.172
Description: The issue is a stack-based buffer overflow in the IASystemInfo.dll ActiveX control. This allows remote attackers to execute arbitrary code via a long ApplicationType property.
Recommendations: For InterActual Player version 2.60.12.0717, consider disabling the IASystemInfo.dll ActiveX control until a patch is available. For Roxio CinePlayer version 3.2, restrict access to the IASystemInfo.dll ActiveX control to minimize the risk of exploitation. For WinDVD version 7.0.27.172, avoid using the ApplicationType property in the affected ActiveX control until the issue is resolved.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-0348

Produtos afetados

Interactual Player
Roxio Cineplayer
Windvd