CVE-2009-1564
published 2010-04-12CVE-2009-1564: Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware…
PriorityP349critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.21%
92.7th percentile
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | movie_decoder | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
vendor_vmware·2010-04-09·CVSS 8.5
CVE-2009-1564 [HIGH] VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
VMSA-2010-0007: VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
a. Windows-based VMware Tools Unsafe Library Loading vulnerability A vulnerability in the way VMware libraries are referenced allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to lure the user that is logged on a Windows Guest Operating System to click on the attacker's file on a network share. This file could be in any file format. The attacker will need to have the ability to host their malicious files on a network share. VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS Security ( http://www.across
Red Hat
neon: billion laughs DoS attack
vendor_redhat·2009-08-18·CVSS 6.5
CVE-2009-2473 [MEDIUM] neon: billion laughs DoS attack
neon: billion laughs DoS attack
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Package: gnome-vfs2 (Red Hat Enterprise Linux 4) - Will not fix
Red Hat
apr-util billion laughs attack
vendor_redhat·2009-06-01·CVSS 6.5
CVE-2009-1955 [MEDIUM] apr-util billion laughs attack
apr-util billion laughs attack
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
GHSA
GHSA-xgj4-xv99-p98g: Heap-based buffer overflow in vmnc
ghsa_unreviewed·2022-05-02
CVE-2009-1564 [HIGH] CWE-119 GHSA-xgj4-xv99-p98g: Heap-based buffer overflow in vmnc
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=866http://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://osvdb.org/63614http://secunia.com/advisories/36712http://secunia.com/advisories/39206http://secunia.com/advisories/39215http://secunia.com/secunia_research/2009-36/http://www.securityfocus.com/bid/39363http://www.securitytracker.com/id?1023838http://www.vmware.com/security/advisories/VMSA-2010-0007.htmlhttp://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=866http://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://osvdb.org/63614http://secunia.com/advisories/36712http://secunia.com/advisories/39206http://secunia.com/advisories/39215http://secunia.com/secunia_research/2009-36/http://www.securityfocus.com/bid/39363http://www.securitytracker.com/id?1023838http://www.vmware.com/security/advisories/VMSA-2010-0007.html
2010-04-12
Published