Vulnerability Bulletins |
Ejecución de código en Windows Media Encoder 9 Series |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Obtener acceso |
Dificulty | Experto |
Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
Property | Value |
Affected manufacturer | Microsoft |
Affected software | Windows Media Encoder 9 Series |
Description |
|
Se ha descubierto una vulnerabilidad de tipo desbordamiento de búfer en Windows Media Encoder 9 Series. La vulnerabilidad reside en un error de comprobación de límites en el control ActiveX "WMEX.DLL". Un atacante remoto podría ejecutar código arbitrario mediante una página Web especialmente diseñada. |
|
Solution |
|
Actualización de software Microsoft (MS08-053) Windows Media Encoder 9 Series / Microsoft Windows 2000 Service Pack 4 / patch WindowsMedia9-KB954156-x86-EN Windows Media Encoder 9 Series / Windows XP Service Pack y Service Pack 3 / patch WindowsMedia9-KB954156-x86-ENU Windows Media Encoder 9 Series / Windows Server 2003 Service Pack 1 y Service Pack 2 / patch WindowsMedia9-KB954156-x86-ENU Windows Media Encoder 9 Series x64 Edition / Windows Server 2003 x64 Edition y Service Pack 2 / patch WindowsMedia9-KB954156-x64-ENU Windows Media Encoder 9 Series / Windows Server 2003 x64 Edition y Service Pack 2 / patch WindowsMedia9-KB954156-32bit-x64-ENU /quiet Windows Media Encoder 9 Series / Windows Vista y Vista Service Pack 1 / patch WindowsMedia9-KB954156-INTL Windows Media Encoder 9 Series x64 Edition / Windows Vista x64 Edition y Service Pack 1 / patch WindowsMedia9-KB954156-x64-INTL Windows Media Encoder 9 Series / Windows Vista x64 Edition y Service Pack 1 / patch WindowsMedia9-KB954156-INTL Windows Media Encoder 9 Series / Windows Server 2008 32-bit Systems / patch WindowsMedia9-KB954156-INTL Windows Media Encoder 9 Series x64 Edition / Windows Server 2008 x64-based Systems / patch WindowsMedia9-KB954156-x64-INTL Windows Media Encoder 9 Series / Windows Server 2008 x64-based Systems / patch WindowsMedia9-KB954156-INTL http://www.microsoft.com/downloads Hewlett-Packard Ver tabla de actualizaciones en: http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01560892-1 http://www.itrc.hp.com/service/patch/mainPage.do |
|
Standar resources |
|
Property | Value |
CVE | CVE-2008-3008 |
BID | 31065 |
Other resources |
|
Microsoft Security Bulletin (MS08-053) http://www.microsoft.com/technet/security/bulletin/ms08-053.mspx HP SECURITY BULLETIN (HPSBST02372) http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01560892-1 |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2008-09-10 |
1.1 | Aviso emitido por HP (HPSBST02372) | 2008-09-25 |