CERT-In Vulnerability Note
CIVN-2021-0377
Multiple Vulnerabilities in Blackmagic DaVinci Resolve Software
Original Issue Date:December 30, 2021
Severity Rating: HIGH
Software Affected
- Blackmagic DaVinci Resolve version 17.3.1.0005
Overview
Multiple vulnerabilities have been reported in Blackmagic Design DaVinci Resolve Software which could be exploited by a remote attacker to perform arbitrary code execution on the targeted system.
Description
These vulnerabilities exist due to flaw in DaVinci Resolves DPDecoder service, which is triggered by heap-based buffer overflow when decoding a video file or an incorrect UUID causing use of uninitialized variable when parsing video files in the affected application.
A remote attacker with no authentication or user interaction could exploit these vulnerabilities to perform arbitrary code execution in the context of the application on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://www.blackmagicdesign.com/support/readme/263d62f31cbb49e0868005059abcb0c9
Vendor Information
https://www.blackmagicdesign.com/products/davinciresolve/
References
https://www.bleepingcomputer.com/news/security/blackmagic-fixes-critical-davinci-resolve-code-execution-flaws/
CVE Name
CVE-2021-40417
CVE-2021-40418
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|