Microsoft Windows Media Player PNG buffer overflow
| win-media-player-png-bo (26788) |
Description:
Microsoft Windows Media Player is vulnerable to a stack-based buffer overflow, caused by improper bounds checking of PNG files. By creating specially-crafted PNG image file and hosting it on a Web site or sending it to a potential victim as an email attachment, a remote attacker could overflow a buffer and execute arbitrary code on the system, once the file is opened.
Platforms Affected:
- Microsoft, Windows 2000 SP4
- Microsoft, Windows 2003 Server x64
- Microsoft, Windows 2003 Server SP1
- Microsoft, Windows Media Player 10
- Microsoft, Windows Media Player 7.1
- Microsoft, Windows Media Player 9
- Microsoft, Windows Media Player XP
- Microsoft, Windows XP Professional x64
- Microsoft, Windows XP SP2
- Microsoft, Windows XP SP1
Remedy:
Apply the appropriate patch for your system, as listed in the latest Microsoft Security Bulletin. See References.
— OR —
Use Microsoft Automatic Update if it is supported by your operating system. The original bulletin issued by Microsoft has been superseded.
Consequences:
Gain Access
References:
- iDefense Advisory: 06.13.06, Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow at http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406.
- Internet Security Systems Protection Alert June 13, 2006, Vulnerability in Windows Media Player Could Allow Code Execution at http://xforce.iss.net/xforce/alerts/id/225.
- Microsoft Security Bulletin MS06-024, Vulnerability in Windows Media Player Could Allow Remote Code Execution (917734) at http://www.microsoft.com/technet/security/Bulletin/MS06-024.mspx.
- ASA-2006-126: Windows Security Updates for June 2006 - (MS06-021 - MS06-032)
- BID-18385: Microsoft Windows Media Player Malformed PNG Remote Code Execution Vulnerability
- CVE-2006-0025: Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.
- OSVDB ID: 26430: Microsoft Windows Media Player PNG Processing Overflow
- SA20626: Windows Media Player PNG Processing Buffer Overflow
- SECTRACK ID: 1016284: Windows Media Player Buffer Overflow in Rendering PNG Images Lets Remote Users Execute Arbitrary Code
- US-CERT VU#608020: Microsoft Windows Media Player PNG processing buffer overflow
- VUPEN/ADV-2006-2322: Microsoft Windows Media Player Remote Code Execution Vulnerability (MS06-024)
Reported:
Jun 13, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
