CVE-2009-4310
Last modified
CVE-2009-4310 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.. EPSS estimates a 24.11% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 2000 | All versions | Sp4 |
| Microsoft | Windows 2003 Server | All versions | Sp2 |
| Microsoft | Windows Xp | All versions | Sp3 |
| Windows | Media Player | All versions | — |
References
- http://secunia.com/advisories/37592Vendor Advisory
- http://support.microsoft.com/kb/954157Patch, Vendor Advisory
- http://support.microsoft.com/kb/955759Patch, Vendor Advisory
- http://support.microsoft.com/kb/976138Patch, Vendor Advisory
- http://www.microsoft.com/technet/security/advisory/954157.mspxPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3440Vendor Advisory
- http://secunia.com/advisories/37592Vendor Advisory
- http://support.microsoft.com/kb/954157Patch, Vendor Advisory
- http://support.microsoft.com/kb/955759Patch, Vendor Advisory
- http://support.microsoft.com/kb/976138Patch, Vendor Advisory
- http://www.microsoft.com/technet/security/advisory/954157.mspxPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3440Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4310?
How severe is CVE-2009-4310?
How do I fix CVE-2009-4310?
Are you affected by CVE-2009-4310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
