Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.
                
            References
                    | Link | Resource | 
|---|---|
| http://secunia.com/secunia_research/2007-37/advisory/ | Vendor Advisory | 
| http://secunia.com/advisories/23032 | Vendor Advisory | 
| http://secunia.com/advisories/23075 | Vendor Advisory | 
| http://www.kb.cert.org/vuls/id/922969 | US Government Resource | 
| http://secunia.com/advisories/24556 | Vendor Advisory | 
| http://www.securityfocus.com/bid/23071 | |
| http://osvdb.org/34315 | |
| http://osvdb.org/34314 | |
| http://www.vupen.com/english/advisories/2007/1042 | Vendor Advisory | 
| http://www.vupen.com/english/advisories/2007/1043 | Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/33186 | |
| http://www.securityfocus.com/archive/1/463405/100/0/threaded | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2007-03-21 12:19
Updated : 2018-10-16 09:32
NVD link : CVE-2007-0348
Mitre link : CVE-2007-0348
JSON object : View
CWE
                
                    
                        
                        CWE-119
                        
            Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
                interactual_technologies
- interactual_player
intervideo
- windvd
roxio
- cineplayer


