Oval Definition:oval:org.mitre.oval:def:1267
Revision Date:2016-02-19Version:49
Title:Win2k,SP4 DirectShow Malicious avi File Vulnerability
Description:QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2005-2128
Platform(s):Microsoft Windows 2000
Product(s):DirectX
Definition Synopsis
  • DirectX packaged with Windows 2000,SP4 has DirectShow Vulnerability
  • Windows 2000 is installed
  • AND SP4 or later Installed
  • AND the version of Quartz.dll is greater than or equal to 6.1.9.726
  • AND the version of Quartz.dll is less than 6.1.9.732
  • OR Standalone DirectX 8 has DirectShow Vulnerability
  • DirectX 8.x Installed
  • AND the version of Quartz.dll is less than 6.3.1.889
  • OR Standalone DirectX 9 has DirectShow Vulnerability
  • DirectX 9.0x Installed
  • AND the version of Quartz.dll is less than 6.3.1.889
  • BACK