This application requires Javascript for optimal performance.

MS.DirectX.DirectShow.Buffer.Overflow

Alias(es)

MS.DirectX.DirectShow.Buffer.Overflow.C, MS.DirectX.DirectShow.Buffer.Overflow.B, MS.DirectX.DirectShow.Buffer.Overflow.A

Release Date

Aug 10, 2005

Severity

low

Impact

Full compromise of the affected system.

Description

This indicates a possible exploit of a Heap-based buffer overflow vulnerability in the Quartz.dll used by Microsoft Directshow.

There exists two heap overflows in the Quartz.dll which handles Midi file execution for windows applications such as Microsoft DirectShow and Internet Explorer. This could allow an attacker to create a Midi file that would allow the execution of arbitrary code when the file is played.

Affected Products

Microsoft DirectX 5.0 - 9.0a.

Recommended Actions

Apply security patch to the system as given in the Microsoft bulletin MS03-030.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2003-0346

Reference/s

http://www.securityfocus.com/bid/8262 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/MS03-030.mspx (MS-ID)

Reference: VID-10594