First published: Sun Dec 13 2009(Updated: )
ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows 2003 Server | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4313 has a critical severity level as it can lead to remote code execution or denial of service due to heap corruption.
To address CVE-2009-4313, ensure that your system is updated with the latest security patches from Microsoft.
CVE-2009-4313 affects Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2.
CVE-2009-4313 is related to a denial of service attack and potential remote code execution through malformed media files.
Currently, the best course of action for CVE-2009-4313 is to apply the official Microsoft updates and patches.