PT-2011-2399 · Videospirit · Videospirit Lite+1

Xsploitedsec

·

Publicado

2011-01-20

·

Atualizado

2011-01-21

·

CVE-2011-0500

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VideoSpirit Pro versions 1.6.8.1 and earlier VideoSpirit Lite version 1.4.0.1 and possibly other versions
Description The issue allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long value attribute. This can be demonstrated using a valitem with the mp3 name.
Recommendations For VideoSpirit Pro versions 1.6.8.1 and earlier, consider avoiding the use of .visprj files containing long value attributes in valitem elements until a fix is available. For VideoSpirit Lite version 1.4.0.1 and possibly other versions, restrict the processing of .visprj files to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0500

Produtos afetados

Videospirit Lite
Videospirit Pro