Executive Summary

Informations
NameCVE-2010-3138First vendor Publication2010-08-27
VendorCveLast vendor Modification2012-04-18

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3138

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:7132
 
Oval ID: oval:org.mitre.oval:def:7132
Title: Indeo Codec Insecure Library Loading Vulnerability
Description: Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.
Family: windows Class: vulnerability
Reference(s): CVE-2010-3138
Version: 7
Platform(s): Microsoft Windows XP
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1
Application1
Os1

Open Source Vulnerability Database (OSVDB)

idDescription
67588Microsoft Windows Indeo Filter Path Subversion Arbitrary DLL Injection Code E...

Internal Sources (Detail)

SourceUrl
EXPLOIT-DBhttp://www.exploit-db.com/exploits/14765
http://www.exploit-db.com/exploits/14788
MISChttp://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4956.php
MShttp://technet.microsoft.com/security/bulletin/MS12-014
OSVDBhttp://osvdb.org/67588
SECUNIAhttp://secunia.com/advisories/41114
VUPENhttp://www.vupen.com/english/advisories/2010/2190

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-10 23:31:09
  • Multiple Updates