Overview
The Microsoft Windows Media Player plug-in for browsers other than Internet Explorer contains a buffer overflow, which may allow a remote attacker to execute arbitrary code.
Description
Windows Media Player Windows Media Player is a multimedia application that comes with Microsoft Windows. |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message), an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause the browser (or any program using the Windows Media Player plug-in) to crash. |
Solution
Apply an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was disclosed by Microsoft, who in turn credit John Cobb of iDefense for reporting the vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2006-0005 |
Severity Metric: | 36.12 |
Date Public: | 2006-02-14 |
Date First Published: | 2006-02-14 |
Date Last Updated: | 2006-02-22 17:53 UTC |
Document Revision: | 12 |