PT-2011-2398 · Videospirit · Videospirit Lite+1
Published
2011-01-20
·
Updated
2017-08-17
·
CVE-2011-0499
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VideoSpirit Pro versions 1.6.8.1 and earlier
VideoSpirit Lite versions 1.4.0.1 and possibly other versions
Description
The issue allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a
valitem element with a long name attribute.Recommendations
For VideoSpirit Pro version 1.6.8.1 and earlier, consider avoiding the use of .visprj files with long
name attributes in valitem elements until a fix is available.
For VideoSpirit Lite version 1.4.0.1 and possibly other versions, restrict the processing of .visprj files to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Videospirit Lite
Videospirit Pro