DivX Player Subtitle Parsing Client-Side Buffer Overflow Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
17 Apr 2008
5294
Views
RISK: Medium Risk
A vulnerability has been identified in DivX Player, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when parsing overly long subtitles, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted SRT file.
Impact
- Remote Code Execution
System / Technologies affected
- DivX Player version 6.7 and prior
Solutions
Disable the automatic loading of subtitles. Do not open untrusted subtitles.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with