Vulnerabilities > CVE-2005-2128 - Unspecified vulnerability in Microsoft Windows Media Player 9
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-050.NASL |
description | The remote host contains a version of DirectX that is vulnerable to a remote code execution flaw. To exploit this flaw, an attacker would need to send a specially malformed .avi file to a user on the remote host and have him open it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20003 |
published | 2005-10-11 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20003 |
title | MS05-050: Vulnerability in DirectShow Could Allow Remote Code Execution (904706) |
code |
|
Oval
accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Dragos Prisaca organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. family windows id oval:org.mitre.oval:def:1149 status accepted submitted 2005-10-12T12:00:00.000-04:00 title Server 2003,SP1 DirectShow Malicious avi File Vulnerability version 70 accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Dragos Prisaca organization Gideon Technologies, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Dragos Prisaca organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. family windows id oval:org.mitre.oval:def:1231 status accepted submitted 2005-10-12T12:00:00.000-04:00 title WinXP,SP2 DirectShow Malicious avi File Vulnerability version 72 accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Dragos Prisaca organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. family windows id oval:org.mitre.oval:def:1267 status accepted submitted 2005-10-12T12:00:00.000-04:00 title Win2k,SP4 DirectShow Malicious avi File Vulnerability version 72 accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Dragos Prisaca organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. family windows id oval:org.mitre.oval:def:1424 status accepted submitted 2005-10-12T12:00:00.000-04:00 title Server 2003 DirectShow Malicious avi File Vulnerability version 70 accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Dragos Prisaca organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. family windows id oval:org.mitre.oval:def:1434 status accepted submitted 2005-10-12T12:00:00.000-04:00 title WinXP,SP1 DirectShow Malicious avi File Vulnerability version 71
References
- http://secunia.com/advisories/17160
- http://secunia.com/advisories/17160
- http://secunia.com/advisories/17172
- http://secunia.com/advisories/17172
- http://secunia.com/advisories/17509
- http://secunia.com/advisories/17509
- http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
- http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
- http://www.eeye.com/html/research/advisories/AD20051011a.html
- http://www.eeye.com/html/research/advisories/AD20051011a.html
- http://www.kb.cert.org/vuls/id/995220
- http://www.kb.cert.org/vuls/id/995220
- http://www.osvdb.org/18822
- http://www.osvdb.org/18822
- http://www.securityfocus.com/bid/15063
- http://www.securityfocus.com/bid/15063
- http://www.us-cert.gov/cas/techalerts/TA05-284A.html
- http://www.us-cert.gov/cas/techalerts/TA05-284A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-050
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-050
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1149
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1149
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1231
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1231
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1267
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1267
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1424
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1424
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1434
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1434