First published: Wed Aug 12 2009(Updated: )
Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1546 is considered critical due to the potential for remote code execution and denial of service.
To address CVE-2009-1546, users should apply the latest security patches provided by Microsoft for their affected Windows operating systems.
CVE-2009-1546 affects Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Server 2003 SP2, and various versions of Windows Vista and Server 2008.
CVE-2009-1546 allows attackers to potentially execute arbitrary code or cause a denial of service through crafted AVI files.
CVE-2009-1546 is an integer overflow vulnerability found in the Avifil32.dll associated with Windows Media file handling.