Vulnerabilities in Microsoft Windows Media Player and Adobe Flash Player
January 23rd, 2008
The Sourcefire VRT is aware of vulnerabilities affecting Microsoft Windows Media Player and Adobe Flash Player. This release also contains rules to address CVE entries CVE-2008-0236, CVE-2008-0237, CVE-2007-3847 and CVE-2008-0248.
Microsoft Windows Media Player Buffer Overflow (CVE-2007-6401): A buffer overflow condition in Microsoft Windows Media Player may be used by an attacker to execute code of their choosing on an affected system via a malicious .mp4 file.
Rules to detect attacks targeting this vulnerability are included in this release and are identified as SIDs 13316 through 13320.
Adobe Flash Player Input Validation Error (CVE-2007-6242): Adobe Flash Player does not correctly validate user input when processing flash animation files. A remote attacker may use these vulnerabilities to execute code on an affected system.
Rules to detect attacks targeting this vulnerability are included in this release and are identified as SIDs 13300 and 13301.
Multiple other rule additions have been made to address vulnerabilities described in CVE entries CVE-2008-0236, CVE-2008-0237, CVE-2007-3847 and CVE-2008-0248.
For Assistance
- Visit the Sourcefire Customer Support site at https://support.sourcefire.com.
- Email Sourcefire Customer Support at support@sourcefire.com.
- Call Sourcefire Customer Support at 410.423.1901 or 1.800.917.4134.
