what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

iDEFENSE Security Advisory 2009-12-08.3

iDEFENSE Security Advisory 2009-12-08.3
Posted Dec 10, 2009
Authored by iDefense Labs | Site idefense.com

iDefense Security Advisory 12.08.09 - Remote exploitation of a heap corruption vulnerability in Microsoft Corp.'s Indeo32 Codec could allow an attacker to execute arbitrary code in the context of the affected user. iDefense has confirmed that ir32_32.dll version 3.24.15.3, as included in fully patched Windows XP as of October 2008, is vulnerable. All previous versions are suspected to be vulnerable.

tags | advisory, remote, arbitrary
systems | windows
SHA-256 | 888ecfafd140b35868b4ef6ea7ef78a496f76eb5faa2b5557aec406398d77738

iDEFENSE Security Advisory 2009-12-08.3

Change Mirror Download
iDefense Security Advisory 12.08.09
http://labs.idefense.com/intelligence/vulnerabilities/
Dec 08, 2009

I. BACKGROUND

Indeo Video is a video codec developed by Intel and included in
Microsoft Windows. For more information about Indeo codec, please the
visit following website:
http://ligos.com/index.php/home/products/indeo/

II. DESCRIPTION

Remote exploitation of a heap corruption vulnerability in Microsoft
Corp.'s Indeo32 Codec could allow an attacker to execute arbitrary code
in the context of the affected user.

This vulnerability especially exists in Indeo32 codec ir32_32.dll. The
Indeo32 codec uses the "IV32" FourCC code inside an AVI file. When this
FourCC code is specified in the "strf" chunk in a AVI file, it tells the
movie player to decode the movie stream using Indeo32 codec. When
malformed data is supplied in the Indeo stream, heap corruption can
happen, which results in an exploitable condition.

III. ANALYSIS

Exploitation allows an attacker to execute arbitrary code on the
affected host in the context of the affected user.

Exploitation of this vulnerability would require a user to open a
malicious media file, usually an AVI file; however, since the
vulnerability is in the streaming component of Microsoft Windows,
attacks can be launched from a malicious website or any application
that delivers Web content. In Windows Explorer, if the Web View Content
is enabled, which is the default setting, a single click will open the
malicious file in the preview pane and trigger the vulnerability. An
attacker can host a malicious AVI file and use social engineering
techniques to trick a user into visiting the site or to deliver the
hostile code to a user via e-mail, for example.

IV. DETECTION

iDefense has confirmed that ir32_32.dll version 3.24.15.3, as included
in fully patched Windows XP as of October 2008, is vulnerable. All
previous versions are suspected to be vulnerable.

V. WORKAROUND

Restrict access to ir32_32.dll by executing Echo y|cacls
"%SystemRoot%\system32\ir32_32.dll" /E /P everyone:N Impact of
workaround: Video encoded with Indeo codec can't be viewed.

VI. VENDOR RESPONSE

Microsoft has released a patch which addresses this issue. This patch
mitigates the vulnerability by blocking the Indeo codec from being
launched in Internet Explorer or Windows Media player, and by removing
the ability to load this codec from Internet zone by any other
applications. For more information, consult its advisory at the
following URL:

http://www.microsoft.com/technet/security/advisory/954157.mspx

VII. CVE INFORMATION

A Mitre Corp. Common Vulnerabilities and Exposures (CVE) number has not
been assigned yet.

VIII. DISCLOSURE TIMELINE

11/11/2008 Initial Vendor Notification
11/11/2008 Initial Vendor Reply
12/08/2009 Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.

Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php

Free tools, research and upcoming events
http://labs.idefense.com/

X. LEGAL NOTICES

Copyright © 2009 iDefense, Inc.

Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDefense. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically,
please e-mail customerservice@idefense.com for permission.

Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition.
There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct,
indirect, or consequential loss or damage arising from use of, or
reliance on, this information.
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    21 Files
  • 27
    Aug 27th
    28 Files
  • 28
    Aug 28th
    15 Files
  • 29
    Aug 29th
    41 Files
  • 30
    Aug 30th
    13 Files
  • 31
    Aug 31st
    313 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close