First published: Mon Dec 06 2010(Updated: )
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build 301548 on Windows, and VMware Server 2.x on Windows does not properly validate an unspecified size field, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted video file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Movie Decoder | <=6.5.5 | |
VMware Movie Decoder | =6.5.3 | |
VMware Movie Decoder | =6.5.4 | |
VMware Movie Decoder | =7.0 | |
VMware Movie Decoder | =7.1.2 | |
Microsoft Windows Operating System | ||
VMware Workstation and ESXi | =6.5.0 | |
VMware Workstation and ESXi | =6.5.1 | |
VMware Workstation and ESXi | =6.5.2 | |
VMware Workstation and ESXi | =6.5.3 | |
VMware Workstation and ESXi | =6.5.4 | |
VMware Workstation and ESXi | =6.5.5 | |
VMware Workstation and ESXi | =7.0 | |
VMware Workstation and ESXi | =7.0.1 | |
VMware Workstation and ESXi | =7.1 | |
VMware Workstation and ESXi | =7.1.1 | |
VMware Workstation and ESXi | =7.1.2 | |
VMware Player | =2.5 | |
VMware Player | =2.5.1 | |
VMware Player | =2.5.2 | |
VMware Player | =2.5.3 | |
VMware Player | =2.5.4 | |
VMware Player | =2.5.5 | |
VMware Player | =3.0 | |
VMware Player | =3.0.1 | |
VMware Player | =3.1 | |
VMware Player | =3.1.1 | |
VMware Player | =3.1.2 | |
VMware Server | =2.0.0 | |
VMware Server | =2.0.1 | |
VMware Server | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4294 has a severity rating that is typically classified as important due to potential remote code execution risks.
To fix CVE-2010-4294, users should upgrade to the latest versions of VMware Movie Decoder, VMware Workstation, or VMware Player as specified in the security advisories.
Affected VMware products include Movie Decoder, Workstation versions prior to 6.5.5 and 7.x before 7.1.2, and Player versions prior to 2.5.5 and 3.x before 7.1.
CVE-2010-4294 is a vulnerability related to frame decompression in the VMnc media codec that can lead to remote code execution.
While CVE-2010-4294 is an older vulnerability, it remains relevant for organizations using unsupported or legacy versions of VMware software.