PT-2011-2398 · Videospirit · Videospirit Lite+1

Published

2011-01-20

·

Updated

2017-08-17

·

CVE-2011-0499

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VideoSpirit Pro versions 1.6.8.1 and earlier VideoSpirit Lite versions 1.4.0.1 and possibly other versions
Description The issue allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long name attribute.
Recommendations For VideoSpirit Pro version 1.6.8.1 and earlier, consider avoiding the use of .visprj files with long name attributes in valitem elements until a fix is available. For VideoSpirit Lite version 1.4.0.1 and possibly other versions, restrict the processing of .visprj files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0499

Affected Products

Videospirit Lite
Videospirit Pro