Vulnerability CVE-2006-6134


Published: 2006-11-27   Modified: 2012-02-12

Description:
Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Windows Media ASX PlayList File Denial Of Service Vulnerability
sehato
28.11.2006

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Microsoft -> Windows media player 

 References:
http://blogs.technet.com/msrc/archive/2006/12/07/public-proof-of-concept-code-for-asx-file-format-isssue.aspx
http://research.eeye.com/html/alerts/zeroday/20061122.html
http://securityreason.com/securityalert/1922
http://securitytracker.com/id?1017354
http://support.avaya.com/elmodocs2/security/ASA-2006-274.htm
http://www.kb.cert.org/vuls/id/208769
http://www.securityfocus.com/archive/1/452352/100/0/threaded
http://www.securityfocus.com/archive/1/453579/100/0/threaded
http://www.securityfocus.com/archive/1/454969/100/200/threaded
http://www.securityfocus.com/bid/21247
http://www.us-cert.gov/cas/techalerts/TA06-346A.html
http://www.vupen.com/english/advisories/2006/4882
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-078
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A669

Copyright 2024, cxsecurity.com

 

Back to Top