PT-2011-2398 · Videospirit · Videospirit Lite+1
Publicado
2011-01-20
·
Atualizado
2017-08-17
·
CVE-2011-0499
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VideoSpirit Pro versions 1.6.8.1 and earlier
VideoSpirit Lite versions 1.4.0.1 and possibly other versions
Description
The issue allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a
valitem element with a long name attribute.Recommendations
For VideoSpirit Pro version 1.6.8.1 and earlier, consider avoiding the use of .visprj files with long
name attributes in valitem elements until a fix is available.
For VideoSpirit Lite version 1.4.0.1 and possibly other versions, restrict the processing of .visprj files to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Videospirit Lite
Videospirit Pro