HIGH
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file
Published Dec 13, 2009
9.3
HIGHCVSS 2.0
EPSS 24.11%
Description
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
Affected products
No data.
AND
- n/a
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://secunia.com/advisories/37592 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1023302 vdb-entryx_refsource_SECTRACKPatch
- http://support.microsoft.com/kb/954157 vendor-advisoryx_refsource_MSKBPatchVendor Advisory
- http://support.microsoft.com/kb/955759 vendor-advisoryx_refsource_MSKBPatchVendor Advisory
- http://support.microsoft.com/kb/976138 vendor-advisoryx_refsource_MSKBPatchVendor Advisory
- http://www.microsoft.com/technet/security/advisory/954157.mspx x_refsource_CONFIRMPatchVendor Advisory
- http://www.osvdb.org/60855 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/508324/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/37251 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/3440 vdb-entryx_refsource_VUPENVendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-09-089/ x_refsource_MISC
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4277 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54642 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54645 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12188 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 13, 2009
Updated Aug 7, 2024
Reserved Dec 12, 2009
Link CVE-2009-4309
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-4277 Assigner mitre
Published Dec 13, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-4277