Nishant Das Patnaik

# Title: Malformed MP4 Local DoS for ffdshow Video Codec (tryouts) rev. 3467 20100713 (x86)

# Author: Nishant Das Patnaik

# EDB-ID: 14582

# Version: <= rev 3512 20100713 (Budled with K-Lite Mega Codec Pack 6.2.0)

# Tested on: Windows XP Pro SP3


# Date: 08/08/2010

# Description: An attacker may just allure the victim to play or just view the thumbnail (in Windows Explorer) of a specially crafted malicious MP4. The video codec crashes all applications, that use it for rendering MP4 files. It also crashes Windows Explorer (explorer.exe) if automatic thumbnail generation of MP4 files is turned on or if you try to view the thumbnails.

# Code: Download

