| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.11803 |
| Kategorie: | Windows |
| Titel: | DirectX MIDI Overflow (819696) |
| Zusammenfassung: | Checks hotfix 819696 |
| Beschreibung: | The remote host is running a version of Windows with a version of DirectX which is vulnerable to a buffer overflow in the module which handles MIDI files. To exploit this flaw, an attacker needs to craft a rogue MIDI file and send it to a user of this computer. When the user attempts to read the file, it will trigger the buffer overflow condition and the attacker may gain a shell on this host. Solution : see http://www.microsoft.com/technet/security/bulletin/MS03-030.mspx Risk factor : High |
| Querverweis: |
BugTraq ID: 7370 BugTraq ID: 8262 Common Vulnerability Exposure (CVE) ID: CVE-2003-0346 Bugtraq: 20030723 EEYE: Windows MIDI Decoder (QUARTZ.DLL) Heap Corruption (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=105899759824008&w=2 http://www.microsoft.com/technet/security/bulletin/MS03-030.asp http://www.cert.org/advisories/CA-2003-18.html CERT/CC vulnerability note: VU#561284 http://www.kb.cert.org/vuls/id/561284 CERT/CC vulnerability note: VU#265232 http://www.kb.cert.org/vuls/id/265232 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:218 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1095 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1104 |
| Copyright | This script is Copyright (C) 2003 Tenable Network Security |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|