PT-2011-2399 · Videospirit · Videospirit Lite+1
Xsploitedsec
·
Publicado
2011-01-20
·
Atualizado
2011-01-21
·
CVE-2011-0500
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VideoSpirit Pro versions 1.6.8.1 and earlier
VideoSpirit Lite version 1.4.0.1 and possibly other versions
Description
The issue allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a
valitem element with a long value attribute. This can be demonstrated using a valitem with the mp3 name.Recommendations
For VideoSpirit Pro versions 1.6.8.1 and earlier, consider avoiding the use of .visprj files containing long
value attributes in valitem elements until a fix is available.
For VideoSpirit Lite version 1.4.0.1 and possibly other versions, restrict the processing of .visprj files to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Videospirit Lite
Videospirit Pro