CVE-2009-0199
published 2009-09-08CVE-2009-0199: Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.02%
91.3th percentile
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | esxi | — | — |
| vmware | movie_decoder | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.
vendor_vmware·2009-09-04·CVSS 9.3
CVE-2009-0199 [CRITICAL] VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.
VMSA-2009-0012: VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.
Several security issues resolved with the latest VMnc codec. The VMware movie decoder contains the VMnc media codec that is required to play back movies recorded with VMware Workstation, VMware Player and VMware ACE, in any compatible media player. The movie decoder is installed as part of VMware Workstation, VMware Player and VMware ACE, or can be downloaded as a stand alone package. Several vulnerabilities in the VMnc codec can be exploited to cause heap-based buffer overflows via specially crafted video files containing incorrect framebuffer parameters. For an attack to be successful the user must be tricked into visiting a malicious web page or opening a malicious video fil
GHSA
GHSA-jqhc-vmcp-q22q: Heap-based buffer overflow in the VMnc media codec in vmnc
ghsa_unreviewed·2022-05-02
CVE-2009-0199 [HIGH] CWE-119 GHSA-jqhc-vmcp-q22q: Heap-based buffer overflow in the VMnc media codec in vmnc
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2009/000065.htmlhttp://secunia.com/advisories/34938http://secunia.com/secunia_research/2009-25/http://www.securityfocus.com/archive/1/506286/100/0/threadedhttp://www.securityfocus.com/bid/36290http://www.vmware.com/security/advisories/VMSA-2009-0012.htmlhttp://www.vupen.com/english/advisories/2009/2553http://lists.vmware.com/pipermail/security-announce/2009/000065.htmlhttp://secunia.com/advisories/34938http://secunia.com/secunia_research/2009-25/http://www.securityfocus.com/archive/1/506286/100/0/threadedhttp://www.securityfocus.com/bid/36290http://www.vmware.com/security/advisories/VMSA-2009-0012.htmlhttp://www.vupen.com/english/advisories/2009/2553
2009-09-08
Published