vendor:
DivX Web Player
by:
shinnai
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: DivX Web Player
Affected Version From: DivX Web Player 1.3.0
Affected Version To: DivX Web Player 1.3.0
Patch Exists: NO
Related CWE:
CPE: a:divx:divx_web_player:1.3.0
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
DivX Web Player 1.3.0 (npdivx32.dll) “Resize” method Denial of Service
This exploit allows an attacker to cause a denial of service by sending a specially crafted request to the vulnerable application. The vulnerability exists in the "Resize" method of the DivX Web Player 1.3.0 (npdivx32.dll) plugin. By providing large values for the arguments of the "Resize" method, an attacker can cause the application to crash due to an access violation error.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to disable or remove the vulnerable plugin from the affected system.