Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-12-11.2

iDefense Security Advisory 12.11.07 – Remote exploitation of a stack buffer overflow vulnerability in Microsoft Corp.’s DirectShow could allow an attacker to execute arbitrary code in the context of the current user. This vulnerability exists in the DirectShow SAMI parser, which is implemented in quartz.dll. When the SAMI parser copies parameters into a stack buffer, it does not properly check the length of the parameter. As such, parsing a specially crafted SAMI file can cause a stack-based buffer overflow. This allows an attacker to execute arbitrary code. iDefense has confirmed Microsoft DirectX 7.x and Microsoft DirectX 8.x are vulnerable. Microsoft DirectX 9.0c or newer is not vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61765/12.11.07-2.txt

Source: https://packetstormsecurity.com/files/61765/iDEFENSE-Security-Advisory-2007-12-11.2.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534