|
Brought to you by:
Suppliers of:
|
|
|
| |
| SlySoft AnyDVD is "capable of removing unwanted movie features, including subtitles and prohibition messages such as copyright and FBI warnings. It also allows you to launch an external application whenever you insert or remove a disc, or prevent 'PC-friendly' software from automatically launching when you insert a video DVD". Positive Technologies Research Team has discovered multiple memory corruption vulnerabilities in SlySoft products. |
| |
Credit:
The information has been provided by Valery Marchuk.
The original article can be found at: http://en.securitylab.ru/lab/PT-2009-11
|
| |
Vulnerable Systems:
* AnyDVD version 6.5.2.2 and previous
* Virtual CloneDrive version 5.4.2.3 and previous
* CloneDVD version 2.9.2.0 and previous
* CloneCD version 5.3.1.3 and previous
Immune Systems:
* AnyDVD version 6.5.2.6
The IOCTL handler in ElbyCDIO.sys 6.0.2.0 and earlier, shipped with AnyDVD, Virtual CloneDrive, CloneDVD and CloneCD, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate buffer data associated with the Irp object, which allows local users to crash the system.
Disclosure Timeline:
02.11.2009 - Vendor notified
02.11.2009 - Vendor replied
02.12.2009 - Sent detailed information
03.06.2009 - Vendor released fixed version of AnyDVD
03.12.2009 - Public disclosure
|
|
|
|
|