CERT-In Vulnerability Note
CIVN-2009-0146
Roxio Creator Image Rendering Integer Overflow Vulnerability
Original Issue Date:December 08, 2009
Severity Rating: HIGH
Systems Affected
- Roxio Creator 2010 10.x
- Roxio Easy Media Creator 9.x
Overview
A integer overflow vulnerability has been reported in Roxio Creater while allocating memory for an image based on its dimensions and can be exploited to corrupt memory via a specially crafted image.
Description
A vulnerability has been reported in an Roxio Creator due to an integer overflow error when processing images with malformed dimensions,
which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted image. Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Solution
Apply the patch provided by vendor Creator 2010 SP1 .
http://www.roxio.com/enu/support/c2010/software_updates.html
Vendor Information
Roxio
http://www.roxio.com/enu/support/c2010/software_updates.html
References
IBM ISS XFORCE
http://xforce.iss.net/xforce/xfdb/54496
Secunia
http://secunia.com/secunia_research/2009-38/
BUGTRAQ
http://www.securityfocus.com/archive/1/archive/1/508165/100/0/threaded
BID
http://www.securityfocus.com/bid/37183
Vupen
http://www.vupen.com/english/advisories/2009/3375
CVE Name
CVE-2009-1566
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|