Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801090
Category:Windows
Title:Microsoft Windows Indeo Codec Multiple Vulnerabilities
Summary:Microsoft Windows Indeo codec is prone to multiple vulnerabilities.
Description:Summary:
Microsoft Windows Indeo codec is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An error in the Indeo41 codec when processing a specific size within the
'movi' record of a IV41 stream can be exploited to cause a heap-based buffer overflow.

- An error in the Indeo41 codec when decompressing a video stream can be
exploited to cause a stack-based buffer overflow.

- An unspecified error in the Indeo codec can be exploited to corrupt memory.

- An error in the Indeo32 codec when decoding a IV32 stream can be exploited
to cause memory corruption.

- Other vulnerabilities also exist and are caused due to unspecified errors
in the Indeo codec and can be exploited to corrupt memory by tricking a user
into viewing specially crafted media content.

Vulnerability Impact:
Successful exploitation will let the remote attackers compromise a vulnerable
system.

Affected Software/OS:
- Microsoft Windows 2K Service Pack 4 and prior

- Microsoft Windows XP Service Pack 3 and prior

- Microsoft Windows 2K3 Service Pack 2 and prior

Solution:
The vendor has released updates, please see the references
for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-4210
BugTraq ID: 37251
http://www.securityfocus.com/bid/37251
Bugtraq: 20091208 Fortinet Advisory: Fortinet Discovers Vulnerability in Indeo Codec (Google Search)
http://www.securityfocus.com/archive/1/508323/100/0/threaded
http://www.fortiguard.com/advisory/FGA-2009-45.html
Microsoft Knowledge Base article: 954157
http://support.microsoft.com/kb/954157
Microsoft Knowledge Base article: 955759
http://support.microsoft.com/kb/955759
Microsoft Knowledge Base article: 976138
http://support.microsoft.com/kb/976138
http://www.osvdb.org/60857
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11677
http://securitytracker.com/id?1023302
http://secunia.com/advisories/37592
http://www.vupen.com/english/advisories/2009/3440
XForce ISS Database: ms-ie-content-code-execution(54645)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54645
XForce ISS Database: ms-ie-indeo-code-execution(54644)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54644
Common Vulnerability Exposure (CVE) ID: CVE-2009-4309
Bugtraq: 20091208 ZDI-09-089: Microsoft Windows Intel Indeo Codec Parsing Heap Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/508324/100/0/threaded
http://zerodayinitiative.com/advisories/ZDI-09-089/
http://www.osvdb.org/60855
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12188
XForce ISS Database: ms-ie-indeo41-bo(54642)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54642
Common Vulnerability Exposure (CVE) ID: CVE-2009-4310
Bugtraq: 20091208 ZDI-09-090: Microsoft Windows Intel Indeo Codec Parsing Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/508335/100/0/threaded
http://zerodayinitiative.com/advisories/ZDI-09-090/
http://www.osvdb.org/60856
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11596
XForce ISS Database: ms-ie-indeo41-codec-bo(54643)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54643
Common Vulnerability Exposure (CVE) ID: CVE-2009-4311
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11975
Common Vulnerability Exposure (CVE) ID: CVE-2009-4312
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11573
Common Vulnerability Exposure (CVE) ID: CVE-2009-4313
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=835
http://www.osvdb.org/60858
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12242
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.