Release date: 2011-12-09
Updated on: 2011-12-13
Affected Systems:
HTC Touch2 T3333
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50999
HTC T3333 is a Windows Mobile 6.5 smartphone.
The HTCVideoPlayer used by HTC Touch2 T3333 has a memory corruption vulnerability in the implementation of parsing stbl elements in 3g2 video format. Remote attackers can exploit this vulnerability to execute arbitrary code in affected applications, this vulnerability may cause denial of service.
<* Source: Celil Unuver
Link: http://www.securityfocus.com/archive/1/520800
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Www.signalsec.com/publications/htcvideo.3g2
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HTC
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.htc.com