Microsoft Windows Media Player Remote PNG Image Format Buffer Overflow Vulnerability
BID:12485
Info
Microsoft Windows Media Player Remote PNG Image Format Buffer Overflow Vulnerability
| Bugtraq ID: | 12485 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1244 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Nortel Networks Symposium Call Center Server (SCCS) Nortel Networks Optivity Telephony Manager (OTM) Nortel Networks Mobile Voice Client 2050 Nortel Networks IP softphone 2050 Microsoft Windows Messenger 4.7 .3000 Microsoft Windows Messenger 4.7 .2009 Microsoft Windows Messenger 5.0 Microsoft Windows Media Services 9.0 Series Microsoft Windows Media Player do NOT use Microsoft Windows Media Player 9.0 Microsoft MSN Messenger Service 6.2 Microsoft MSN Messenger Service 6.1 |
| Not Vulnerable: |
Microsoft Windows Messenger 5.1 Microsoft Windows Media Player 8.0 Microsoft Windows Media Player 7.1 Microsoft Windows Media Player 6.4 Microsoft Windows Media Player 10.0 |
Discussion
Microsoft Windows Media Player Remote PNG Image Format Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects the Portable Network Graphics (PNG) image format processing functionality of Microsoft Windows Media Player. This issue is due to a failure of the application to properly validate the size of image data prior to copying it into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the SYSTEM user. This will facilitate unauthorized access and privilege escalation.
A remote buffer overflow vulnerability affects the Portable Network Graphics (PNG) image format processing functionality of Microsoft Windows Media Player. This issue is due to a failure of the application to properly validate the size of image data prior to copying it into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the SYSTEM user. This will facilitate unauthorized access and privilege escalation.
Exploit / POC
Microsoft Windows Media Player Remote PNG Image Format Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows Media Player Remote PNG Image Format Buffer Overflow Vulnerability
Solution:
Microsoft has released updated to address this vulnerability in supported versions of the software. Fixes for Windows Media Player on Windows 98/98SE/ME may be obtained through Windows Update.
Nortel Networks has released security advisory 2005005516-2 acknowledging
this issue. Please see the referenced advisory for further information.
Microsoft Windows Media Player 9.0
Microsoft Windows Messenger 5.0
Microsoft Windows Media Player do NOT use
Microsoft Windows Media Services 9.0 Series
Microsoft Windows Messenger 4.7 .2009
Microsoft Windows Messenger 4.7 .3000
Solution:
Microsoft has released updated to address this vulnerability in supported versions of the software. Fixes for Windows Media Player on Windows 98/98SE/ME may be obtained through Windows Update.
Nortel Networks has released security advisory 2005005516-2 acknowledging
this issue. Please see the referenced advisory for further information.
Microsoft Windows Media Player 9.0
-
Microsoft Security Update for Windows Media Player 9 Series (KB885492)
http://www.microsoft.com/downloads/details.aspx?familyid=A52279DC-3B6C -4720-8192-45657EDBB14F&displaylang=en
Microsoft Windows Messenger 5.0
-
Microsoft Windows Messenger 5.1
http://www.microsoft.com/downloads/details.aspx?familyid=A8D9EB73-5F8C -4B9A-940F-9157A3B3D774&displaylang=en
Microsoft Windows Media Player do NOT use
-
Microsoft Security Update for Windows Media Player 9 Series (KB885492)
http://www.microsoft.com/downloads/details.aspx?familyid=A52279DC-3B6C -4720-8192-45657EDBB14F&displaylang=en
Microsoft Windows Media Services 9.0 Series
-
Microsoft Security Update for Windows Media Player 9 Series (KB885492)
http://www.microsoft.com/downloads/details.aspx?familyid=A52279DC-3B6C -4720-8192-45657EDBB14F&displaylang=en
Microsoft Windows Messenger 4.7 .2009
-
Microsoft Security Update for Windows Messenger (KB887472)
For Windows Messenger 4.7.0.2009 running on Windows XP Service Pack 1.
http://www.microsoft.com/downloads/details.aspx?familyid=E3DC209B-AD57 -49E1-BB90-6FA2CA8763A6&displaylang=en
Microsoft Windows Messenger 4.7 .3000
-
Microsoft Security Update for Windows Messenger (KB887472)
For Windows Messenger 4.7.0.3000 running on Windows XP Service Pack 2.
http://www.microsoft.com/downloads/details.aspx?familyid=1DCC9628-E2D0 -496F-B4F2-3AFEFA0A0156&displaylang=en
References
Microsoft Windows Media Player Remote PNG Image Format Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS05-009 (Microsoft)
- Windows Media Player Homepage (Microsoft)