Threat Monitor
Troj.Exploit.JS.DirektShow.gen
| Aliases: | |
|---|---|
| Pattern: | 201008311330 |
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
|---|---|---|---|
|
|
|
|
Roxio CinePlayer is prone to a heap-based buffer overflow vulnerability.
The issue occurs in the SetIAPlayerName() method in the Roxio CinePlayer ActiveX control in the IAManager.dll with the CLSID:EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC. By persuading a victim to view a specially-crafted Web page that passes an overly long string to the SetIAPlayerName() function, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the browser to crash.
Affected: Roxio CinePlayer 3.2
The issue occurs in the SetIAPlayerName() method in the Roxio CinePlayer ActiveX control in the IAManager.dll with the CLSID:EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC. By persuading a victim to view a specially-crafted Web page that passes an overly long string to the SetIAPlayerName() function, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the browser to crash.
Affected: Roxio CinePlayer 3.2


