CVE-2008-5259
16.04.2009, 15:12
Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow.Enginsight
Vendor | Product | Version |
---|---|---|
divx | divx_web_player | 𝑥 ≤ 1.4.2.7 |
divx | divx_web_player | 1.0.1 |
divx | divx_web_player | 1.0.2 |
divx | divx_web_player | 1.1 |
divx | divx_web_player | 1.1.0 |
divx | divx_web_player | 1.2 |
divx | divx_web_player | 1.2.0 |
divx | divx_web_player | 1.3 |
divx | divx_web_player | 1.3.0 |
divx | divx_web_player | 1.3.1 |
divx | divx_web_player | 1.4 |
divx | divx_web_player | 1.4.0:beta2 |
divx | divx_web_player | 1.4.1:beta1 |
divx | divx_web_player | 1.4.2:beta2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References