Secunia Security Advisory - Parvez Anwar has discovered some vulnerabilities in InterVideo WinDVD Media Center, which can be exploited by malicious people to cause a DoS (Denial of Service).
b17ddb22efd62da14cdc68bad7d081e300d094f9caa3ba338c7d18a81e5653df
----------------------------------------------------------------------
A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI
has been released. The new version includes many new and advanced
features, which makes it even easier to stay patched.
Download and test it today:
https://psi.secunia.com/
Read more about this new version:
https://psi.secunia.com/?page=changelog
----------------------------------------------------------------------
TITLE:
InterVideo WinDVD Media Center Denial of Service Vulnerabilities
SECUNIA ADVISORY ID:
SA28910
VERIFY ADVISORY:
http://secunia.com/advisories/28910/
CRITICAL:
Less critical
IMPACT:
DoS
WHERE:
>From local network
SOFTWARE:
InterVideo WinDVD Media Center
http://secunia.com/product/17529/
DESCRIPTION:
Parvez Anwar has discovered some vulnerabilities in InterVideo WinDVD
Media Center, which can be exploited by malicious people to cause a
DoS (Denial of Service).
The vulnerabilities are caused due to NULL-pointer dereference errors
within InterVideo IMC Server (IMCSvr.exe) and InterVideo Home Theater
(IHT.exe) when handling received packets. These can be exploited to
crash the affected processes via a specially crafted packet
containing two CRLF sequences.
The vulnerabilities are confirmed in version 2.11.15.0 of the
installer package.
SOLUTION:
Use in a trusted network environment only.
PROVIDED AND/OR DISCOVERED BY:
Parvez Anwar
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------