CVE-2009-0894

EUVD-2009-0891
Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
xvidxvid
𝑥
≤ 1.2.1
xvidxvid
1.1.0
xvidxvid
1.1.1
xvidxvid
1.1.2
xvidxvid
1.1.3
xvidxvid
1.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xvidcore
bookworm
2:1.3.7-1
fixed
bullseye
2:1.3.7-1
fixed
sid
2:1.3.7-1
fixed
trixie
2:1.3.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xvidcore
dapper
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected