The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build 301548 on Windows, and VMware Server 2.x on Windows does not properly validate an unspecified size field, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted video file.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 01:20
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.vmware.com/pipermail/security-announce/2010/000112.html - | |
References | () http://osvdb.org/69596 - | |
References | () http://secunia.com/advisories/42482 - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/514995/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/45169 - | |
References | () http://www.securitytracker.com/id?1024819 - | |
References | () http://www.vmware.com/security/advisories/VMSA-2010-0018.html - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2010/3116 - Vendor Advisory |
Information
Published : 2010-12-06 21:05
Updated : 2024-11-21 01:20
NVD link : CVE-2010-4294
Mitre link : CVE-2010-4294
CVE.ORG link : CVE-2010-4294
JSON object : View
Products Affected
vmware
- movie_decoder
- workstation
- server
- player
microsoft
- windows
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')