ðòïåëôù
áòèé÷
Security-alerts @yandex-team.ru
óôáôøé
ðåòóïîáìøîïå
ðòïçòáííù
ðéûéôåðéóøíá
> > TITLE: > Windows Media Player Skin Handling Code Execution Vulnerabilities > > SECUNIA ADVISORY ID: > SA26433 > > VERIFY ADVISORY: > http://secunia.com/advisories/26433/ > > CRITICAL: > Highly critical > > IMPACT: > System access > > WHERE: > From remote > > SOFTWARE: > Microsoft Windows Media Player 7.x > http://secunia.com/product/1084/ > Microsoft Windows Media Player 9.x > http://secunia.com/product/1085/ > Microsoft Windows Media Player 10.x > http://secunia.com/product/4208/ > Microsoft Windows Media Player 11.x > http://secunia.com/product/11280/ > > DESCRIPTION: > Two vulnerabilities have been reported in Windows Media Player, which > can be exploited by malicious people to compromise a user's system. > > 1) An error in the parsing of header information in skin files can be > exploited to execute arbitrary code on a user's system by tricking the > user into opening a malicious skin file. > > 2) An error in the decompression of skin files can be exploited to > execute arbitrary code on a user's system by tricking the user into > opening a malicious skin file. > > SOLUTION: > Apply patches. > > Windows Media Player 7.1 for Windows 2000 SP4: > http://www.microsoft.com/downloads/details.aspx?FamilyId=9f46b > 1fc-ee7b-437f-9492-67d003711021 > > Windows Media Player 9 for Windows 2000 SP4 / Windows XP SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=bd4a6 > 474-5fde-415e-840e-7d973cb71c95 > > Windows Media Player 10 for Windows XP SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=48f5a > 9d3-b859-4cb6-a68e-abde76a14782 > > Windows Media Player 10 for Windows XP Professional X64 Edition > (optionally with SP2): > http://www.microsoft.com/downloads/details.aspx?FamilyId=94958 > 0be-cbb3-4271-8ca0-0ead7f2d8801 > > Windows Media Player 10 for Windows Server 2003 SP1/SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=8d9f1 > fdf-6d4c-44d4-9b5f-bdbe8ac28d7f > > Windows Media Player 10 for Windows Server 2003 x64 Edition > (optionally with SP2): > http://www.microsoft.com/downloads/details.aspx?FamilyId=2c04c > 7f2-728e-43bd-8574-26e411fcd129 > > Windows Media Player 11 for Windows XP SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=a690d > 042-1137-4aaf-bd0e-565ea04d1f2b > > Windows Media Player 11 for Windows XP Professional X64 Edition > (optionally with SP2): > http://www.microsoft.com/downloads/details.aspx?FamilyId=bdc89 > f34-c1ff-46ab-b52d-c02d51c5c373 > > Windows Media Player 11 for Windows Vista: > http://www.microsoft.com/downloads/details.aspx?FamilyId=80e51 > 67c-4f75-4ce3-8b15-2f50958deec8 > > Windows Media Player 11 for Windows Vista x64 Edition: > http://www.microsoft.com/downloads/details.aspx?FamilyId=bf30b > 714-d6e7-47ea-b79e-84c18370a661 > > PROVIDED AND/OR DISCOVERED BY: > The vendor credits Piotr Bania and ZDI. > > ORIGINAL ADVISORY: > MS07-047 (KB936782): > http://www.microsoft.com/technet/security/Bulletin/MS07-047.mspx >
Copyright © Lexa Software, 1996-2009.