47047Third-party advisory
http://secunia.com/advisories/47047 CVE-2011-5003
AVID Media Composer Phonetic Indexer - Remote Stack Buffer Overflow (Metasploit)
Record summary
CVE-2011-5003 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBAVID Media Composer Phonetic Indexer - Remote Stack Buffer Overflow (Metasploit)ExploitDB exploitby Nick FreemanNot analyzed1 file
MetasploitAvid Media Composer 5.5 - Avid Phonetic Indexer Buffer OverflowMetasploit exploitby vt [nick.freeman <vt [nick.freeman@security-assessment.com]>Not analyzed1 file
References
718183exploit
http://www.exploit-db.com/exploits/18183 77376vdb entry
http://www.osvdb.org/77376 security-assessment.com
http://www.security-assessment.com/files/documents/advisory/Avid_Media_Composer-Phonetic_Indexer-Remote_Stack_Buffer_Overflow.pdf 50843vdb entry
http://www.securityfocus.com/bid/50843 avidmedia-avidphoneticindexer-bo(71514)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/71514 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-5003