CVE-2009-0893

EUVD-2009-0890
Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a "missing resync marker range check" and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
xvidxvid
𝑥
≤ 1.2.1
xvidxvid
1.1.0
xvidxvid
1.1.1
xvidxvid
1.1.2
xvidxvid
1.1.3
xvidxvid
1.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xvidcore
bookworm
2:1.3.7-1
fixed
bullseye
2:1.3.7-1
fixed
sid
2:1.3.7-1
fixed
trixie
2:1.3.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xvidcore
dapper
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected