First published: Wed Dec 12 2007(Updated: )
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows Server 2003 | =datacenter_edition | |
Microsoft Windows Server 2003 | =enterprise_edition | |
Microsoft Windows Server 2003 | =standard | |
Microsoft Windows Server 2003 | =web_edition | |
Microsoft Windows Vista | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft DirectX | =5.2 | |
Microsoft DirectX | =6.1 | |
Microsoft DirectX | =7.0 | |
Microsoft DirectX | =7.0a | |
Microsoft DirectX | =7.1 | |
Microsoft DirectX | =8.0 | |
Microsoft DirectX | =8.0a | |
Microsoft DirectX | =8.1 | |
Microsoft DirectX | =8.1a | |
Microsoft DirectX | =8.1b | |
Microsoft DirectX | =8.2 | |
Microsoft DirectX | =9.0a | |
Microsoft DirectX | =9.0b | |
Microsoft DirectX | =9.0c | |
Microsoft DirectX | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3901 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2007-3901, ensure that you apply the latest security updates from Microsoft for all affected versions of DirectX.
CVE-2007-3901 affects Microsoft DirectX versions 5.2 through 10.0 across various Windows operating systems.
CVE-2007-3901 is a stack-based buffer overflow vulnerability in the DirectShow SAMI parser.
Yes, CVE-2007-3901 can be exploited remotely by attackers using a crafted SAMI file.