CVE-2014-10024

Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:divx:directshowdemuxfilter:*:*:*:*:*:*:*:*
OR cpe:2.3:a:divx:player:*:*:*:*:*:*:*:*
cpe:2.3:a:divx:web_player:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:03

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2014/Apr/283 - Exploit () http://seclists.org/fulldisclosure/2014/Apr/283 - Exploit
References () http://www.securityfocus.com/bid/67086 - () http://www.securityfocus.com/bid/67086 -

Information

Published : 2015-01-13 11:59

Updated : 2024-11-21 02:03


NVD link : CVE-2014-10024

Mitre link : CVE-2014-10024

CVE.ORG link : CVE-2014-10024


JSON object : View

Products Affected

divx

  • web_player
  • directshowdemuxfilter
  • player
CWE
CWE-189

Numeric Errors