vendor:
AVIPreview
by:
BraniX
7.5
CVSS
HIGH
Denial of Service
476
CWE
Product Name: AVIPreview
Affected Version From: 0.26 Alpha
Affected Version To: 0.26 Alpha
Patch Exists: Yes
Related CWE: N/A
CPE: a:divx_digest:avipreview
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Home Edition
2011
AVIPreview 0.26 Alpha Denial of Service
AVIPreview 0.26 Alpha is vulnerable to a denial of service attack. The application reads memory via a null pointer, causing an Access Violation Exception. An attacker can force something malicious to the ECX register (.data is RW) and gain code execution. To exploit this vulnerability, an attacker must generate a malicious AVI file, open it in AVIPreview, select 'No' when the MessageBox with an error appears, navigate to the File menu and pick the recent file (which points to the malicious AVI file). This will cause the application to crash.
Mitigation:
Update to the latest version of AVIPreview.