Vulnerabilities > CVE-2009-1566 - Numeric Errors vulnerability in Roxio Creator and Easy Media Creator
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | ROXIO_CREATOR_IMG_OVERFLOW.NASL |
description | According to its version, the Roxio Creator install on the remote host is 9.x earlier than or equal to 9.0.136. It is, therefore, affected by an integer overflow vulnerability related to image handling that could allow arbitrary code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 70144 |
published | 2013-09-26 |
reporter | This script is Copyright (C) 2013-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/70144 |
title | Roxio Creator 9.x <= 9.0.136 Image Handling Integer Overflow |
code |
|
References
- http://secunia.com/advisories/36069
- http://secunia.com/advisories/36069
- http://secunia.com/secunia_research/2009-38/
- http://secunia.com/secunia_research/2009-38/
- http://www.securityfocus.com/archive/1/508165/100/0/threaded
- http://www.securityfocus.com/archive/1/508165/100/0/threaded
- http://www.securityfocus.com/bid/37183
- http://www.securityfocus.com/bid/37183
- http://www.vupen.com/english/advisories/2009/3375
- http://www.vupen.com/english/advisories/2009/3375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54496
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54496