Internet Security Software - Computer Security Software - Security Software
Software Security Solutions background
 
 

mountains

LinkScanner Knowledge Base


spacer

Exploit: MS06-006 WMP overflow (CVE-2006-0005)

Dated Posted:

04.10.2007

Posted By:

Roger Thompson - CTO

Category:

Research

 
 

Microsoft created the Windows Media Player Plug-in so users of browsers other than Internet Explorer could view embedded Windows Media format content from within non-Microsoft browsers, such as Firefox, with this optional plug-in installed.

Unfortunately, due to an oversite in the coding of the plug-ins, it is possible to craft a long embed src tag in such a way that it will cause a buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, allowing remote code injection and execution, if either of these plug-ins is set up as the default application to handle media files.

Initially, this vulnerability was responsibly (privately) reported to Microsoft on 31 August, 2005. Microsoft issued correcting patches on 14 February 2006 as noted in (MSO6-006), on the same day the exploit was announced publicly.

CVE-2006-0005

 

 

Return to Knowledge Base

Anti Virus Software | Eset NOD32 | Kaspersky | Eset Smart Security | Spyware Removal Software | Spysweeper
Remove Adware |LinkScanner | LinkScanner Online | Firewalls | Outpost | SonicWALL | Disaster Recovery
Spam Blocker
| Security Tools | Computer Security Tips | Layered Security Model | Security Software Resources
Solution Certifications | Trusted Reviews | Security Goal | Security Links
Partners | Press Releases | White Papers | About Us Home


Contact Software Security Solutions at (303) 232-9070
Site Map | Privacy Policy | Legal Notice | Home

© 2008 Software Security Solutions. All rights reserved.