Name:
Divx.Player.SRT.Buffer.Overflow
Released Date:
May 20 2008
Severity:
critical
CVE:
2008-1912
Bugtraq:
28799

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
This indicates an attempt to exploit a buffer-overflow vulnerability in DivX Player.

This vulnerability is caused by the application's failure to properly check the bounds of user-supplied input, allowing execution of arbitrary code. A remote attacker may be able to exploit this by using an overly long subtitle in a .SRT file.
 
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
 
Affected Products
DivX Player 6.7 build 6.7.0.22 and earlier.
Aliases
References
http://www.securityfocus.com/bid/28799
http://www.frsirt.com/english/advisories/2008/1235
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1912
Recommended Actions
Do not open untrusted subtitles.

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED