BlazeDVD.PLF.Playlist.Buffer.Overflow

Release DateOct 09, 2008
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt to exploit a buffer-overflow vulnerability in BlazeVideo BlazeDVD software.

The vulnerability is caused by an error when the vulnerable software handles a malicious playlist. It allows a remote attacker to execute arbitrary code via sending a crafted .PLF file with long filename.
Affected ProductsBlazeVideo HDTV versions 2.1 and prior
BlazeDVD Standard and Professional 5.0
Recommended ActionsUninstall or disable the affected software until patch is released
Do not open untrusted playlists.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-6199
Reference/shttp://www.securityfocus.com/bid/21337 (BugTraq)
http://www.vupen.com/english/advisories/2006/4764 (FrSIRT)
Reference: VID-15863