漏洞信息详情
Windows Media Player .ASX ‘Version’缓冲区溢出漏洞
- CNNVD编号:CNNVD-200106-163
- 危害等级: 高危
- CVE编号:
CVE-2001-0242
- 漏洞类型:
缓冲区溢出
- 发布时间:
2001-06-27
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
microsoft - 漏洞来源:
Discovered and pos… -
漏洞简介
Microsoft Windows Media Player 7及其早期版本存在目录遍历漏洞。远程攻击者借助(1).ASX文件的超长version标签,或者(2)超长banner标签, 正如在MS:MS00-090讨论的“.ASX缓冲区溢出”漏洞的变体执行任意命令。
漏洞公告
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com
参考网址
来源:US-CERT Vulnerability Note: VU#187528
名称: VU#187528
链接:http://www.kb.cert.org/vuls/id/187528
来源: MS
名称: MS01-029
链接:http://www.microsoft.com/technet/security/bulletin/ms01-029.asp
来源: XF
名称: mediaplayer-asx-bo(5574)
链接:http://xforce.iss.net/xforce/xfdb/5574
来源: BID
名称: 2686
链接:http://www.securityfocus.com/bid/2686
来源: BID
名称: 2677
链接:http://www.securityfocus.com/bid/2677
来源: BUGTRAQ
名称: 20010506 Re: Microsoft Media Player ASX Parser buffer overflow vulnerability
链接:http://www.securityfocus.com/archive/1/183906
来源: BUGTRAQ
名称: 20010502 Microsoft Media Player ASX Parser buffer overflow vulnerability
链接:http://www.securityfocus.com/archive/1/181419