The IT Security Suite Network's Blogs
« Obama’s cybersecurity plan gets cautious praiseMr. President, solving the IT Security issues will require government to look up to us rather than down on us, more education and awareness please »

Security Alert - [SA35274] Xvid Multiple Vulnerabilities

Permalink 06/01/09 22:38, by Brett A. Scudder, Categories: General IT News, Updates and Information , Tags: it security, secunia, xvid vulnerability

Link: http://secunia.com/advisories/35274/

TITLE:
Xvid Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA35274

VERIFY ADVISORY:
http://secunia.com/advisories/35274/

DESCRIPTION:
Some vulnerabilities have been reported in Xvid, which can be exploited by malicious people to potentially compromise an application using the library.

The vulnerabilities are caused due to boundary errors within the “decoder_iframe()", “decoder_pframe()", and “decoder_bframe()”
functions in src/decoder.c. These can be exploited to potentially corrupt memory via specially crafted video files.

Successful exploitation may allow execution of arbitrary code.

The vulnerabilities are reported in versions prior to 1.2.2.

SOLUTION:
Update to version 1.2.2.

PROVIDED AND/OR DISCOVERED BY:
The vendor credits John McDonald and Christopher Valasek of IBM X-Force.

ORIGINAL ADVISORY:
Xvid:
http://www.xvid.org/News.64.0.html?&cHash=0170b4e439&tx_ttnews[backPid]=64&tx_ttnews[tt_news]=7
http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&r2=1.81

———————————————————————-

About:
This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities.

Subscribe:
http://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only use those supplied by the vendor.

Leave a comment »

No feedback yet

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
PoorExcellent
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)
September 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    
Here are all The IT Security Suite Network's Blogs aggregated on this page. It automatically aggregates all posts from all other blogs. This allows you to easily track everything that is posted on this system. For specific blogs please see the various categories.

Search

Categories

TITSSN's Main Blogs Suite

TITSSN's Members and Associates Suite

The IT Security Suite Network's Chapters Suite

Events and Happenings Suite

TITSSN's Executives Suite

TITSSN's Vendors Suite

The ThreatTrix - IT Security Alerts and Info

TITSSN's Photoblog

TITSSN's Partners/Groups Suite

TITSSN's Polls

The IT Security City

Our Webcasts and Presentations

XML Feeds

TITSSN's Linkblog

free blog software

©2010 by ~TITSSN~

Contact | Blog theme by Asevo | blog software | webhost | monetize blog