Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

DiVX City Global DiVX Zenith Player AviFixer ActiveX Control Remote Buffer Overflow Vulnerability

Global DiVX Zenith Player (GDiVX Player) AviFixer ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

An attacker may exploit this issue by enticing victims into opening a malicious webpage or HTML email that invokes the affected control.

All versions of Global DiVX Zenith Player with 'fix.dll' version 1.0.0.1 are considered vulnerable to this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus