HTTP: CyberLink PowerDVD PlayList File Handling Stack Overflow
This signature detects attempts to exploit a known stack overflow vulnerability in CyberLink PowerDVD product. It is due to inadequate boundary checks when loading playlist files. A remote attacker could exploit this vulnerability to create a stack overflow condition on the target system. Successful exploitation could lead to denial-of-service conditions. Upon processing a malicious playlist file, the PowerDVD process will terminate due to a stack overflow condition, which triggers a Denial of Service condition.
Extended Description
PowerDVD is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied input. Successfully exploiting these issues may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions. PowerDVD 8.0 is vulnerable; prior versions may also be affected.
Affected Products
Cyberlink powerdvd
References
BugTraq: 30341
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Cyberlink