Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-0894

Опубликовано: 02 июн. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10

Описание

Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

2:1.2.2+debian-0ubuntu2
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

2:1.2.2+debian-0ubuntu2
maverick

not-affected

2:1.2.2+debian-0ubuntu2
natty

not-affected

2:1.2.2+debian-0ubuntu2
oneiric

not-affected

2:1.2.2+debian-0ubuntu2

Показывать по

Ссылки на источники

EPSS

Процентиль: 88%
0.04313
Низкий

10 Critical

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.

debian
больше 16 лет назад

Heap-based buffer overflow in the decoder_create function in the initi ...

github
больше 3 лет назад

Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 88%
0.04313
Низкий

10 Critical

CVSS2