Windows Media Player .ASX 'Version' Buffer Overflow Vulnerability
BID:2686
Info
Windows Media Player .ASX 'Version' Buffer Overflow Vulnerability
| Bugtraq ID: | 2686 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0242 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered and posted to Bugtraq by ByteRage <[email protected]> on May 6, 2001. |
| Vulnerable: |
Microsoft Windows Media Player 7.0 Microsoft Windows Media Player 6.4 Microsoft Windows Media Player 6.3 |
| Not Vulnerable: | |
Discussion
Windows Media Player .ASX 'Version' Buffer Overflow Vulnerability
Windows Media Player is an application used for digital audio, and video content viewing. An unsafe buffer copy involving remotely-obtained data exists in the Active Stream Redirector (ASX) component in Windows Media Player.
When parsing .ASX files, the 'HREF' value in the <VERSION> tag is copied into a local variable without bounds checking. As a result, it is possible to cause a stack overrun if this field exceeds the predefined length limits. This vulnerability can be exploited by an attacker to gain access to victim hosts.
Remote attackers may be able to exploit vulnerable clients if a malicious .ASX file is placed on a webserver.
Though not confirmed, it is increasingly likely that there is a single underlying problem with the handling of HREF attributes which is leading to these vulnerabilities. See Bugtraq IDs 1980 and 2677 (links in reference section).
Windows Media Player is an application used for digital audio, and video content viewing. An unsafe buffer copy involving remotely-obtained data exists in the Active Stream Redirector (ASX) component in Windows Media Player.
When parsing .ASX files, the 'HREF' value in the <VERSION> tag is copied into a local variable without bounds checking. As a result, it is possible to cause a stack overrun if this field exceeds the predefined length limits. This vulnerability can be exploited by an attacker to gain access to victim hosts.
Remote attackers may be able to exploit vulnerable clients if a malicious .ASX file is placed on a webserver.
Though not confirmed, it is increasingly likely that there is a single underlying problem with the handling of HREF attributes which is leading to these vulnerabilities. See Bugtraq IDs 1980 and 2677 (links in reference section).
Exploit / POC
Windows Media Player .ASX 'Version' Buffer Overflow Vulnerability
The following exploit was tested on Windows NT 4.0 SP6a and has been provided by Gary O'leary-Steele <[email protected]>:
The following exploit was tested on Windows NT 4.0 SP6a and has been provided by Gary O'leary-Steele <[email protected]>:
Solution / Fix
Windows Media Player .ASX 'Version' Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Windows Media Player .ASX 'Version' Buffer Overflow Vulnerability
References:
References: