News
Contributed by: Lauren Gerber
Date: July 13, 2009
The world of computer security vulnerabilities is a very complicated one. More and more vulnerabilities are emerging on a more frequent basis which is obviously causing a problem for day to day computer users who do not know much about computers. There is a new vulnerability which may cause a problem for those users out there who love listening to music. The vulnerability which I shall be bringing to your attention today has recently been discovered in M3U/M3L To ASX/WPL. M3U/M3L To ASX/WPL is a small and simple program, yet it is very effective as well as user friendly. It is geared to help users convert old playlists into newer playlists. That is what it does in a nutshell. One of the formats it allows users to convert to, is the M3U from the popular Windows Media Player, which includes some of the following files: 7bdf02b635cc942381f3db3f0fe9..., po2_9c84b74ca66444bd8a157120..., wmp10_wmpband.dll, wmp10_wmplayer.exe as well as wmp10_wmploc.dll. Why did this vulnerability occur? This is a good question and the answer is simple: This vulnerability has been caused due to a boundary error which takes place when processing certain files names, which are included in the playlists that are opened. The fundamental issue with this weakness, is that it may be exploited by malicious characters in order to create a stack based buffer over flow attack. This takes place when a user is manipulated into opening up an ".m3u", ".m3l", or ".asx"playlist, which may contain a longer than normal entry. If attackers exploit this vulnerability with various levels of success and precision, then the possibility is very high that the execution of arbitrary code may take place. System access, without the authorization which is required under normal circumstances, could also be obtained by attackers . I would also like to bring it to your attention that this vulnerability has been rated as moderately critical. It has been confirmed in version 1.1 and users need to be aware of the factor that other versions may also be affected at this current point in time. The solution to this vulnerability is for all users to never open up any files that are not trusted. I wish you all the best of luck and only time will tell what the future holds for music and computers. |
|||||
Software Downloads



User Comments