ID

VAR-200905-0370


TITLE

D-Link MPEG4 Viewer ActiveX Control Multiple Heap Overflow Vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2009-2802

DESCRIPTION

D-Link MPEG4 Viewer is an ActiveX control installed on the D-Link webcam client.  The D-Link MPEG4 Viewer ActiveX control does not correctly validate the input passed to the SetFilePath () and SetClientCookie () methods. If a user is tricked into visiting a malicious webpage and transmitting long input parameters to the above method, a heap overflow can be triggered, causing arbitrary instructions to be executed.

Trust: 0.6

sources: CNVD: CNVD-2009-2802

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2009-2802

AFFECTED PRODUCTS

vendor:nonemodel: - scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2009-2802

EXTERNAL IDS

db:CNVDid:CNVD-2009-2802

Trust: 0.6

sources: CNVD: CNVD-2009-2802

SOURCES

db:CNVDid:CNVD-2009-2802

LAST UPDATE DATE

2022-05-04T10:02:01.715000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2009-2802date:2009-05-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2009-2802date:2009-05-15T00:00:00