CVE-2014-10024

Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:divx:directshowdemuxfilter:*:*:*:*:*:*:*:*
OR cpe:2.3:a:divx:player:*:*:*:*:*:*:*:*
cpe:2.3:a:divx:web_player:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-01-13 11:59

Updated : 2024-02-28 12:20


NVD link : CVE-2014-10024

Mitre link : CVE-2014-10024

CVE.ORG link : CVE-2014-10024


JSON object : View

Products Affected

divx

  • web_player
  • directshowdemuxfilter
  • player
CWE
CWE-189

Numeric Errors