Vulnerability Bulletins |
Ejecución de código en Windows Media Player 11 |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Obtener acceso |
Dificulty | Experto |
Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
Property | Value |
Affected manufacturer | Microsoft |
Affected software | Windows Media Player 11 |
Description |
|
Se ha descubierto una vulnerabilidad en Windows Media Player 11. La vulnerabilidad reside en un error al procesar frecuencias de muestreo. Un atacante remoto podría ejecutar código arbitrario mediante un fichero de audio especialmente diseñado enviado mediante "streaming" desde un Windows Media Server usando Windows Media Player 11. |
|
Solution |
|
Actualización de sfotware Microsoft (MS08-054) Windows Media Player 11 / Windows XP SP2 y SP3 / patch WindowsMedia11-KB954154-x86-ENU.exe Windows Media Player 11 / Windows XP Professional x64 Edition y Windows XP Professional x64 Edition SP2 / patch WindowsMedia11-KB954154-x64-ENU.exe Windows Media Player 11 / Windows Vista y Windows Vista SP1 / patch Windows6.0-KB954154-x86.msu Windows Media Player 11 / Windows Vista x64 Edition y Windows Vista x64 Edition SP1 / patch Windows6.0-KB954154-x64.msu Windows Media Player 11 / Windows Server 2008 32-bit / patch Windows6.0-KB954154-x86.msu Windows Media Player 11 / Windows Server 2008 x64 / patch Windows6.0-KB954154-x64.msu Hewlett-Packard Ver tabla de actualizaciones en: http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01560892-1 http://www.itrc.hp.com/service/patch/mainPage.do |
|
Standar resources |
|
Property | Value |
CVE | CVE-2008-2253 |
BID | |
Other resources |
|
Microsoft Security Bulletin (MS08-054) http://www.microsoft.com/technet/security/Bulletin/ms08-054.mspx HP SECURITY BULLETIN (HPSBST02372) http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01560892-1 |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2008-09-15 |
1.1 | Aviso emitido por HP (HPSBST02372) | 2008-09-25 |