CVE-2009-1564: Buffer Overflow
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1564?
CVE-2009-1564 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2009-1564?
To fix CVE-2009-1564, you should update VMware Workstation, Player, or Movie Decoder to version 6.5.4 Build 246459 or later.
Which products are affected by CVE-2009-1564?
CVE-2009-1564 affects VMware Workstation versions 6.5.0 through 6.5.3, VMware Player versions 2.5.0 through 2.5.3, and VMware Server 2.x.
Can CVE-2009-1564 be exploited remotely?
Yes, CVE-2009-1564 can be exploited remotely by using crafted VMnc media files.
What type of vulnerability is CVE-2009-1564?
CVE-2009-1564 is a heap-based buffer overflow vulnerability.