Feeds

Media player users beware: more vulns ahead

Targeting Windows Media Player and Winamp

Intelligent flash storage arrays

Security researchers are warning that popular media players offered by Microsoft and AOL are vulnerable to attacks that can completely compromise a user's PC.

Attack code has already been released for the bug, which has been confirmed in a codec used by older versions of Windows Media Player, made by Microsoft, and in AOL's Winamp. A Symantec researcher has warned that users of other players may also be at risk because the vulnerability itself resides in a commonly used MP4 codec produced by a company called 3ivx Technologies.

"The exploit works by supplying victims with a maliciously formed MP4 file," Raymond Ball wrote for Symantec's DeepSight Threat Management System. "When a victim unknowingly clicks a link that appears safe, the MP4 content is delivered, causing the exploit to run."

A researcher who goes by the name SYS 49152 released exploit code here, here and here that targets Windows Media Player 6.4 and Windows Media Player Classic, which are made by Microsoft, and AOL's Winamp version 3.5. Each uses the 3ivx MP4 codec, which is vulnerable to a stack overflow.

Secunia describes the Windows Media Player vulnerabilities as "highly critical," the second-highest rating on Secunia's five-tier scale. The vulnerability reporting service didn't have a rating for the Winamp vulnerability.

No patch is available. Ball recommends users remove the codec or disable media players that use the MP4 codec until the hole is plugged. That strikes us as overkill. Taking care not to click on suspicious links in browsers and email programs should suffice.

The vulnerabilities are the latest reminders of the exposure that can come from using a media player. Two weeks ago, a security bug was discovered in the way Apple's QuickTime that leaves PC and Mac users alike at risk of remote hijacking. Apple has yet to acknowledge the vulnerability, which resides in the way QuickTime interacts with servers that stream audio and video. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.