CVE-2009-0894

Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
xvidxvid
𝑥
≤ 1.2.1
xvidxvid
1.1.0
xvidxvid
1.1.1
xvidxvid
1.1.2
xvidxvid
1.1.3
xvidxvid
1.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xvidcore
sid
2:1.3.7-1
fixed
trixie
2:1.3.7-1
fixed
bookworm
2:1.3.7-1
fixed
bullseye
2:1.3.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xvidcore
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored