複数の VMware 製品の VMnc メディアコーデック内にあるフレーム復元機能における任意のコードを実行される脆弱性
| Title |
複数の VMware 製品の VMnc メディアコーデック内にあるフレーム復元機能における任意のコードを実行される脆弱性
|
| Summary |
複数の VMware 製品の VMnc メディアコーデック内にあるフレーム復元機能には、不特定のサイズフィールドを適切に検証しないため、任意のコードを実行される、またはサービス運用妨害 (DoS) 状態となる脆弱性が存在します。
|
| Possible impacts |
第三者により、巧妙に細工されたビデオファイルを介して、任意のコードを実行される、またはサービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
Dec. 2, 2010, midnight |
| Registration Date |
Dec. 27, 2010, 3:33 p.m. |
| Last Update |
Dec. 27, 2010, 3:33 p.m. |
|
CVSS2.0 : 危険
|
| Score |
9.3
|
| Vector |
AV:N/AC:M/Au:N/C:C/I:C/A:C |
Affected System
| VMware |
|
VMware Movie Decoder
|
|
VMware Player 2.5.x
|
|
VMware Player 3.x
|
|
VMware Server 2.x
|
|
VMware Workstation 6.5.x
|
|
VMware Workstation 7.x
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2010年12月27日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2010-4294
| Summary |
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build 301548 on Windows, and VMware Server 2.x on Windows does not properly validate an unspecified size field, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted video file.
|
| Publication Date |
Dec. 7, 2010, 6:05 a.m. |
| Registration Date |
Jan. 29, 2021, 11:08 a.m. |
| Last Update |
Nov. 21, 2024, 10:20 a.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:vmware:movie_decoder:*:*:*:*:*:*:*:* |
|
6.5.5 |
|
|
| cpe:2.3:a:vmware:movie_decoder:6.5.3:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:movie_decoder:6.5.4:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:movie_decoder:7.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:movie_decoder:7.1.2:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
| Configuration2 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:vmware:workstation:6.5.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:6.5.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:6.5.2:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:6.5.3:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:6.5.4:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:6.5.5:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:7.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:7.0.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:7.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:7.1.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:workstation:7.1.2:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
| Configuration3 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:vmware:player:2.5:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:2.5.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:2.5.2:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:2.5.3:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:2.5.4:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:2.5.5:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:3.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:3.0.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:3.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:3.1.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:player:3.1.2:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
| Configuration4 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:vmware:server:2.0.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:server:2.0.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:vmware:server:2.0.2:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
Related information, measures and tools
Common Vulnerabilities List