Windows Media Player Remote Stack Buffer Overflow Vulnerability

Windows Media Player is prone to a stack-based buffer-overflow issue because it fails to perform adequate boundary checks on user-supplied data.

Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.

Windows Media Player 6.4 is vulnerable; other versions may also be affected.

To exploit this issue an attacker must entice an unsuspecting user to open a malicious MP4 file.

Note: Proof of Concept is available

http://www.securityfocus.com/bid/26773/discuss

Published Sun, Dec 9 2007 4:47 by donna

Comments

# Q: When is a Vulnerable Application not a Vulnerable Application? | ID Fortification

Pingback from  Q: When is a Vulnerable Application not a Vulnerable Application? | ID Fortification

# Q: When is a Vulnerable Application not a Vulnerable Application? | Stop ID Thieves

Pingback from  Q: When is a Vulnerable Application not a Vulnerable Application? | Stop ID Thieves

# Q: When is a Vulnerable Application not a Vulnerable Application? | ID Theft Review

Pingback from  Q: When is a Vulnerable Application not a Vulnerable Application? | ID Theft Review

# Q: When is a Vulnerable Application not a Vulnerable Application? | ID Theft Product

Pingback from  Q: When is a Vulnerable Application not a Vulnerable Application? | ID Theft Product

# Q: When is a Vulnerable Application not a Vulnerable Application? | Stop Id Thieves

Pingback from  Q: When is a Vulnerable Application not a Vulnerable Application? | Stop Id Thieves