Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 09-16-2007, 07:17 AM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
Popular Chinese Movie Player BoaFeng Vulnerable

Popular Chinese Movie Player BoaFeng Vulnerable
<p>It has recently been discovered that BoaFeng Storm, a movie player written in Chinese and widely used in Chinese-speaking countries, contains multiple buffer-overflow vulnerabilies, some of which are being actively exploited. The vulnerabilities are related to the ActiveX control used by the software and a vulnerable computer simply needs to browse a Web site, which contains exploit code, to be compromised. Successful exploitation then allows remote execution of arbitrary code in the context of the application using the ActiveX control (in this case Internet Explorer) and allows the attacker to take full control of the compromised computer. Failed exploit attempts may lead to denial-of-service conditions, possibly resulting in the browser crashing.<br />
<br />
The vulnerabilities have been confirmed in version 2.8 and beta version 2.9, although other versions may also be affected, and at the time of this writing the vulnerabilities remain unpatched. Security Focus have also released information (<a href="http://www.securityfocus.com/bid/25601/info">BID 25601</a>) for it that includes a work-around until a vendor-supplied patch is made available. Symantec has added a heuristic detection for the exploit, <a href="http://www.symantec.com/ja/jp/enterprise/security_response/writeup.jsp?docid=2007-091307-4700-99">Bloodhound.Exploit.160</a>.<br />
<br />
ZhenHan Liu is credited with this discovery.</p>
http://www.symantec.com/enterprise/security_response/weblog/2007/09/popular_chinese_movie_player_b.html
http://www.symantec.com/enterprise/security_response/weblog/2007/09/popular_chinese_movie_player_b.html
Thu, 13 Sep 2007 01:47:36 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 10:32 AM.


    Firefox 2