Windows Media Player ASX PlayList File Heap Overflow Vulnerability
BID:21247
Info
Windows Media Player ASX PlayList File Heap Overflow Vulnerability
| Bugtraq ID: | 21247 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-6134 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2006 12:00AM |
| Updated: | Jun 18 2008 11:11PM |
| Credit: | [email protected] reported this vulnerability. |
| Vulnerable: |
Microsoft Windows Media Player 9.0 Microsoft Windows Media Player 8.0 Microsoft Windows Media Player 7.1 Microsoft Windows Media Player 6.4 Microsoft Windows Media Player 10.0 Microsoft Windows Media Format 9.5 HP Storage Management Appliance 2.1 Avaya Web Messenger 0 Avaya VPNmanagerTM Console 0 Avaya Visual Vector Client 0 Avaya Visual Messenger TM 0 Avaya Unified Messenger (r) 0 Avaya Unified Communication Center Avaya Speech Access 0 Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya Outbound Contact Management 0 Avaya Operational Analyst 0 Avaya OctelDesignerTM 0 Avaya OctelAccess(r) Server 0 Avaya Network Reporting 0 Avaya Modular Messaging (MAS) 3.0 Avaya Modular Messaging (MAS) Avaya IP Softphone 0 Avaya IP Agent 0 Avaya Interaction Center - Voice Quick Start 0 Avaya Interaction Center 0 Avaya Integrated Management Avaya Enterprise Management 0 Avaya CVLAN Avaya Contact Center Express 0 Avaya Computer Telephony 0 Avaya CMS Supervisor 0 Avaya Basic Call Management System Reporting Desktop server Avaya Basic Call Management System Reporting Desktop 0 Avaya Agent Access 0 |
| Not Vulnerable: |
Microsoft Windows Media Format 7.1 Microsoft Windows Media Format 11 |
Discussion
Windows Media Player ASX PlayList File Heap Overflow Vulnerability
Windows Media Player is prone to a heap-overflow issue.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected user. Failed exploit attempts likely result in application crashes.
Windows Media Player is prone to a heap-overflow issue.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected user. Failed exploit attempts likely result in application crashes.
Exploit / POC
Windows Media Player ASX PlayList File Heap Overflow Vulnerability
A proof-of-concept ASX file has been provided:
A proof-of-concept ASX file has been provided:
Solution / Fix
Windows Media Player ASX PlayList File Heap Overflow Vulnerability
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Windows Media Format 9.5
Microsoft Windows Media Player 6.4
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Windows Media Format 9.5
-
Microsoft Security Update for Windows 2000 (KB923689)
http://www.microsoft.com/downloads/details.aspx?familyid=ef2dbcb6-cc8e -4299-a1e6-e6db202b41d5 -
Microsoft Security Update for Windows Media Format 9.5 Series x64 Edition (KB923689)
http://www.microsoft.com/downloads/details.aspx?familyid=c5ece3cd-ac7b -46b4-99dc-74a6b0f323d0 -
Microsoft Security Update for Windows Server 2003 (KB923689)
http://www.microsoft.com/downloads/details.aspx?familyid=0cb64ad7-9b54 -4e26-9125-e9e9a0c0fc65 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB923689)
http://www.microsoft.com/downloads/details.aspx?familyid=2203c66c-6722 -42d5-a7dc-ac5e71402542 -
Microsoft Security Update for Windows XP (KB923689)
http://www.microsoft.com/downloads/details.aspx?familyid=19ca4b44-2b60 -4270-9c42-f5063c627f91 -
Microsoft Security Update for Windows XP x64 Edition (KB923689)
http://www.microsoft.com/downloads/details.aspx?familyid=7322327f-abd9 -4595-98dd-a19ef41652fc
Microsoft Windows Media Player 6.4
-
Microsoft Security Update for Windows Media Player 6.4 for Windows Server 2003 x64 Edition (KB925398)
Microsoft Windows Server 2003 x64 Edition and Microsoft Windows Server 2003 x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=a4fca647-01b7 -4201-85e8-1647412742b0&displaylang=en -
Microsoft Security Update for Windows Media Player 6.4 for Windows XP x64 Edition (KB925398)
Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=a5240618-5975 -4ef2-9749-4cccddb786c7&displaylang=en -
Microsoft Security Update for Windows Media Player 6.4 for Windows (KB925398)
http://www.microsoft.com/downloads/details.aspx?familyid=e63ccdc3-a2ed -4ef6-b8a1-3f8be4b2726d -
Microsoft Security Update for Windows Media Player 6.4 for Windows Server 2003 x64 Edition (KB925398)
http://www.microsoft.com/downloads/details.aspx?familyid=a4fca647-01b7 -4201-85e8-1647412742b0 -
Microsoft Security Update for Windows Media Player 6.4 for Windows XP x64 Edition (KB925398)
http://www.microsoft.com/downloads/details.aspx?familyid=a5240618-5975 -4ef2-9749-4cccddb786c7
References
Windows Media Player ASX PlayList File Heap Overflow Vulnerability
References:
References:
- ASA-2006-274 - MS06-078 Vulnerability in Windows Media Format Could Allow Remote (Avaya)
- Critical Vulnerabilities in MS06-078 (IT-ISAC)
- EEYEZD-20061122 (eEye Digital Security)
- Microsoft Security Bulletin MS06-078 (Microsoft)
- Public Proof of Concept Code for ASX File Format Isssue (Microsoft)
- Technical Cyber Security Alert TA06-346A - Microsoft Updates for Multiple Vulner (US-CERT)
- Vulnerability Note VU#208769 (US-CERT)
- Windows Media Player Homepage (Microsoft)
- ASX Playlists and Jumping to Conclusions (Carl Jongsma)
- Windows Media ASX PlayList File Denial Of Service Vulnerability ([email protected])