Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Microsoft Media Player and Project Server - Minor New Vulnerabilities

Both of these are rated as low-risk by FrSIRT  
 
Windows Media Player - New Denial of Service Vulnerability
http://www.frsirt.com/english/advisories/2006/5039

QUOTE: A vulnerabilitiy has been identified in Microsoft Windows Media Player, which could be exploited by attackers to cause a denial of service. This issue is due to a division by zero error when handling a specially crafted MIDI file with a header chunk containing malformed fields (i.e. number of tracks and delta time), which could be exploited by attackers to crash a vulnerable application via a specially crafted file.

Microsoft Project Server 2003 File Information Disclosure Vulnerability
http://www.frsirt.com/english/advisories/2006/5038

QUOTE: A vulnerability has been identified in Microsoft Project Server 2003, which could be exploited by malicious users to gain knowledge of sensitive information. This issue is due to an error when handling HTTP POST requests passed to the "logon/pdsrequest.asp" script, which could be exploited by authenticated attackers to disclose the username and password of the "MSProjectUser" SQL account.