Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Media player users beware: more vulnerabilities ahead.
Search Topic:
Uniqs:
234
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
AVG anit-spy and Object Data Question »
« TCPView - System Process (TCP)  
AuthorAll Replies


Shriyash
Sungazer
Premium
join:2005-02-23
PuNe, InDiA

Media player users beware: more vulnerabilities ahead.

By Dan Goodin in San Francisco.
Published Monday 10th December 2007 23:59 GMT

Security researchers are warning that popular media players offered by Microsoft and AOL are vulnerable to attacks that can completely compromise a user's PC.

Attack code has already been released for the bug, which has been confirmed in a codec used by older versions of Windows Media Player, made by Microsoft, and in AOL's Winamp. A Symantec researcher has warned that users of other players may also be at risk because the vulnerability itself resides in a commonly used MP4 codec produced by a company called 3ivx Technologies.

"The exploit works by supplying victims with a maliciously formed MP4 file," Raymond Ball wrote for Symantec's DeepSight Threat Management System. "When a victim unknowingly clicks a link that appears safe, the MP4 content is delivered, causing the exploit to run."

A researcher who goes by the name SYS 49152 released exploit code here, here and here that targets Windows Media Player 6.4 and Windows Media Player Classic, which are made by Microsoft, and AOL's Winamp version 3.5. Each uses the 3ivx MP4 codec, which is vulnerable to a stack overflow.

Secunia describes the Windows Media Player vulnerabilities as "highly critical," the second-highest rating on Secunia's five-tier scale. The vulnerability reporting service didn't have a rating for the Winamp vulnerability.

No patch is available. Ball recommends users remove the codec or disable media players that use the MP4 codec until the hole is plugged. That strikes us as overkill. Taking care not to click on suspicious links in browsers and email programs should suffice.

The vulnerabilities are the latest reminders of the exposure that can come from using a media player. Two weeks ago, a security bug was discovered in the way Apple's QuickTime that leaves PC and Mac users alike at risk of remote hijacking. Apple has yet to acknowledge the vulnerability, which resides in the way QuickTime interacts with servers that stream audio and video.
Full article here
--
Alex Jones Bullhorning Bilderberg.
»www.jonesreport.com/articles/211···erg.html
Forums » Up and Running » Security » SecurityAVG anit-spy and Object Data Question »
« TCPView - System Process (TCP)  


Wednesday, 09-Dec 10:12:15 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [197] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [55] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [50] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [21] AT&T Releases Network Reporting iPhone App
Most people now reading
· Comcast refused to install 400' feet. [Comcast HSI]
· Is sleeping similar to being dead? [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· SERVERS DoWN!!! [World of Warcraft]
· Comcast Customers: Would You Prefer Metered Billing? [Comcast HSI]
· New PvE Content [World of Warcraft]
· buffs, nerfs, and 3.3 [World of Warcraft]
· [ Classes] ATTN Death Knights - Post your spec for critique! [World of Warcraft]