CERT-In Vulnerability Note
CIVN-2005-0097
Microsoft msdds.dll COM object Vulnerability
Original Issue Date:October 12, 2005
Updated: October 12, 2005
Severity Rating: HIGH
Software Affected
Microsoft DirectX 7.0 on Microsoft Windows 2000 with Service Pack 4 Microsoft DirectX 8.1 on - Microsoft Windows XP SP 1 and SP 2,
- Windows XP Professional x64 Edition
- Windows Server 2003 Service Pack 1
- Windows Server 2003 SP 1 for Itanium-based Systems
- Windows Server 2003 x64 Edition
- Windows 98 SE and Windows Millennium Edition
Microsoft DirectX 8.0, 8.0a, 8.1, 8.1a, 8.1b, and 8.2 when installed on Windows 2000 Service Pack 4 Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c on Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows Server 2003
Overview
A buffer overflow vulnerability has been reported in Microsoft DirectShow which could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Description
Microsoft DirectShow is a programming architecture which is used for streaming media on Microsoft Windows operating systems. This vulnerability is caused due to an unchecked buffer in DirectShow which allows a buffer overflow in applications or components that use DirectShow.
This flaw could be exploited by an attacker by sending a maliciously crafter media file such as AVI file to an application that uses DirectShow.
Solution
Apply appropriate security update mentioned in Microsoft Security Bulletin
MS05-050
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS05-050.mspx
References
Secunia Advisory:SA17160
http://secunia.com/advisories/17160/
US-CERT Vulnerability Note VU#995220
http://www.kb.cert.org/vuls/id/995220
CVE Name
CAN-2005-2128
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|