Name:
MS.Windows.Media.Player.SAMI.Code.Execution
Released Date:
Jun 10 2008
Severity:
critical
CVE:
2008-1444
MS Bulletin:
ms08-033
Bugtraq:
29578

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
This indicates an attempt to exploit a remote code execution vulnerability in Microsoft Windows Media Player.

The vulnerability is due to the way Windows Media Player handles supported file formats. This vulnerability is caused by a buffer overflow in QUARTZ.DLL when it tries to parse SAMI files containing long caption class names.
 
Impact
System Compromise
Denial of Service
 
Affected Products
Windows 2000 SP4
Windows XP SP2 and Windows XP SP3
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition SP2
Windows Server 2003 SP1 and Windows Server 2003 SP2
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition SP2
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista and Windows Vista SP1
Windows Vista x64 Edition and Windows Vista x64 Edition SP1
Windows Server 2008 for 32-bit Systems
Windows Server 2008 for x64-based Systems
Windows Server 2008 for Itanium-based Systems
Aliases
References
http://www.microsoft.com/technet/security/Bulletin/ms08-033.mspx
http://www.securityfocus.com/bid/29578
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1444
Recommended Actions
Apply the update:
http://www.microsoft.com/technet/security/Bulletin/ms08-033.mspx.

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED