CVE-2014-10024

Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:divx:directshowdemuxfilter:*:*:*:*:*:*:*:*
OR cpe:2.3:a:divx:web_player:*:*:*:*:*:*:*:*
cpe:2.3:a:divx:player:*:*:*:*:*:*:*:*

Information

Published : 2015-01-13 03:59

Updated : 2015-01-13 16:30


NVD link : CVE-2014-10024

Mitre link : CVE-2014-10024


JSON object : View

CWE
CWE-189

Numeric Errors

Advertisement

dedicated server usa

Products Affected

divx

  • directshowdemuxfilter
  • web_player
  • player