RealSecure Server Sensor, RealSecure Network, BlackICE PC Protection, Proventia Network MFS, Proventia-G 1.1 and earlier, Proventia Network IDS, IBM Security Server Protection for Windows, BlackICE Server Protection, Proventia Desktop, Proventia Network IPS, Virtual Server Protection for Vmware, Proventia Server IPS for Linux technology:
This signature detects a very large AVI movie file which could lead to remote code execution in vulnerable applications.
High
RealSecure Server Sensor: XPU 28.150, RealSecure Network: XPU 28.150, BlackICE PC Protection: 3.6cri, Proventia Network MFS: XPU 28.150, Proventia-G 1.1 and earlier: XPU 28.150, Proventia Network IDS: XPU 28.150, IBM Security Server Protection for Windows: 2.1.14.2400, IBM Security Server Protection for Windows: 2.0.300.2290, IBM Security Server Protection for Windows: 1.0.914.2290, BlackICE Server Protection: 3.6.cri, Proventia Desktop: 2290, Proventia Network IPS: XPU 28.150, Virtual Server Protection for Vmware: 1.0, Proventia Server IPS for Linux technology: 28.150
IBM AIX, WindRiver BSDOS, Linux Kernel, Sun Solaris, Microsoft Windows, Data General DG/UX, SCO SCO Unix, Compaq Tru64, Xvid Xvid: 1.1.2, Xvid Xvid: 1.1.3, Xvid Xvid: 1.2.1
Unauthorized Access Attempt
Xvid is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when handling error conditions by the DirectShow component of the Xvid codec. By persuading a victim to set up a rendering pipeline, a remote attacker could overflow a buffer to corrupt memory and execute arbitrary code on the system.
Upgrade to the latest version of Xvid (1.2.2 or later), available from the Xvid Web site. See References.
Xvid Web site
Xvid.org: Xvid 1.2.2 released
http://www.xvid.org/News.64.0.html?&cHash=0170b4e439&tx_ttnews[backPid]=64&tx_ttnews[tt_news]=7
Xvid CVS Repository
Diff of /xvidcore/src/decoder.c
http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&r2=1.81
ISS X-Force
Application movie file buffer overflow
http://www.iss.net/security_center/static/44655.php
CVE
CVE-2009-0894
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0894