May I ask if this also will get fixed next time around on the next update?
Or DEP and ASLR (standard Windows protection add-ins)
Full details below of the exploit are below..
Regards,
C.
Secunia Advisory SA41228
DVDFab Insecure Library Loading Vulnerability
Secunia Advisory SA41228
Get alerted and manage the vulnerability life cycle
Free Trial
Release Date 2010-09-01
Popularity 442 views
Comments 0 comments
Criticality level Highly criticalHighly critical
Impact System access
Where From remote
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Software:
DVDFab 7.x
DVDFab 8.x
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been discovered in DVDFab, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the application bundling a vulnerable version of mfc90.dll, which loads libraries (e.g. dwmapi.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a dvdfab6 file located on a remote WebDAV or SMB share.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in version 7.0.4.0 and confirmed in version 8.0.0.5. Other versions may also be affected.
Solution
Do not open untrusted files.
Provided and/or discovered by
Reported by an unknown person.
Original Advisory
Or DEP and ASLR (standard Windows protection add-ins)
Full details below of the exploit are below..
Regards,
C.
Secunia Advisory SA41228
DVDFab Insecure Library Loading Vulnerability
Secunia Advisory SA41228
Get alerted and manage the vulnerability life cycle
Free Trial
Release Date 2010-09-01
Popularity 442 views
Comments 0 comments
Criticality level Highly criticalHighly critical
Impact System access
Where From remote
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Software:
DVDFab 7.x
DVDFab 8.x
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been discovered in DVDFab, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the application bundling a vulnerable version of mfc90.dll, which loads libraries (e.g. dwmapi.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a dvdfab6 file located on a remote WebDAV or SMB share.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in version 7.0.4.0 and confirmed in version 8.0.0.5. Other versions may also be affected.
Solution
Do not open untrusted files.
Provided and/or discovered by
Reported by an unknown person.
Original Advisory
Comment