Skip to main content

DivX Player Subtitle Parsing Client-Side Buffer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 17 Apr 2008 4453 Views

RISK: Medium Risk

A vulnerability has been identified in DivX Player, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when parsing overly long subtitles, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted SRT file.


Impact

  • Remote Code Execution

System / Technologies affected

  • DivX Player version 6.7 and prior

Solutions

Disable the automatic loading of subtitles. Do not open untrusted subtitles.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link