CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
96.2%
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
Vendor | Product | Version | CPE |
---|---|---|---|
microsoft | windows_2000 | * | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* |
microsoft | windows_2003_server | * | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:* |
microsoft | windows_2003_server | * | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:* |
microsoft | windows_2003_server | * | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:* |
microsoft | windows_xp | * | cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:* |
microsoft | windows_xp | - | cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:* |
microsoft | windows_xp | - | cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:* |
windows | media_player | * | cpe:2.3:a:windows:media_player:*:*:*:*:*:*:*:* |
secunia.com/advisories/37592
securitytracker.com/id?1023302
support.microsoft.com/kb/954157
support.microsoft.com/kb/955759
support.microsoft.com/kb/976138
www.microsoft.com/technet/security/advisory/954157.mspx
www.osvdb.org/60856
www.securityfocus.com/archive/1/508335/100/0/threaded
www.securityfocus.com/bid/37251
www.vupen.com/english/advisories/2009/3440
zerodayinitiative.com/advisories/ZDI-09-090/
exchange.xforce.ibmcloud.com/vulnerabilities/54643
exchange.xforce.ibmcloud.com/vulnerabilities/54645
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11596