Vulnerability Description
Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a "missing resync marker range check" and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xvid | Xvid | <= 1.2.1 |
Related Weaknesses (CWE)
References
- http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c
- http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&r2=1.81ExploitPatch
- http://secunia.com/advisories/35274Vendor Advisory
- http://www.securityfocus.com/bid/35156
- http://www.vupen.com/english/advisories/2009/1468Vendor Advisory
- http://www.xvid.org/News.64.0.html?&cHash=0170b4e439&tx_ttnews%5BbackPid%5D=64&t
- https://www.it-isac.org/postings/cyber/alertdetail.php?id=4634&selyear=2009&menu
- http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c
- http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&r2=1.81ExploitPatch
- http://secunia.com/advisories/35274Vendor Advisory
- http://www.securityfocus.com/bid/35156
- http://www.vupen.com/english/advisories/2009/1468Vendor Advisory
- http://www.xvid.org/News.64.0.html?&cHash=0170b4e439&tx_ttnews%5BbackPid%5D=64&t
- https://www.it-isac.org/postings/cyber/alertdetail.php?id=4634&selyear=2009&menu
FAQ
What is CVE-2009-0893?
CVE-2009-0893 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute a...
How severe is CVE-2009-0893?
CVE-2009-0893 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0893?
Check the references section above for vendor advisories and patch information. Affected products include: Xvid Xvid.