vendor:
Media Composer
by:
Nick Freeman
7.5
CVSS
HIGH
Remote Stack Buffer Overflow
119
CWE
Product Name: Media Composer
Affected Version From: AVID Media Composer <= 5.5.3
Affected Version To: AVID Media Composer <= 5.5.3
Patch Exists: NO
Related CWE: CVE-2011-4858
CPE: a:avid:media_composer
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-1359-1/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0005-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0074/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0475/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-ELSA-2012-0475/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0474/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0076/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-7f5ccb1d-439b-11e1-bc16-0023ae8e59f0/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-4858/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-4858/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-4858/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2011-4858/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2011-4858/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0680/, https://www.rapid7.com/db/?q=CVE-2011-4858&type=&page=2, https://www.rapid7.com/db/?q=CVE-2011-4858&type=&page=2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2011
AVID Media Composer Phonetic Indexer Remote Stack Buffer Overflow
Security-Assessment.com discovered a remote stack buffer overflow vulnerability in a network daemon that ships with Avid Media Composer 5.5, named AvidPhoneticIndexer.exe. By sending a large request to the listening network service, it is possible to overwrite the stack of the process and gain arbitrary code execution.
Mitigation:
Host and network based firewalling are recommended as workarounds to limit the exposure of the vulnerable service.