vendor:
AVIPreview
by:
BraniX
7,5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: AVIPreview
Affected Version From: 0.26 Alpha
Affected Version To: 0.26 Alpha
Patch Exists: Yes
Related CWE: N/A
CPE: a:divx_digest:avipreview
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Home Edition
2011
AVIPreview 0.26 Alpha Denial of Service Vulnerability
AVIPreview 0.26 Alpha is vulnerable to a Denial of Service attack. The application reads memory via a null pointer, causing an Access Violation Exception. An attacker can force something malicious to the ECX register (.data is RW) and gain code execution. To exploit this vulnerability, an attacker must open a specially crafted AVI file in AVIPreview, select 'No' when the MessageBox with an error appears, navigate to the File menu and pick the recent file (which points to the AVI file). This will cause the application to crash.
Mitigation:
Upgrade to a version of AVIPreview that is not vulnerable to this attack.