News
Contributed by: Lauren Gerber
Date: July 29, 2009
A new vulnerability has been discovered. Firstly, it is important for everyone to know that just because a vulnerability exists, that does not mean you need to go and delete the entire program. There are solutions to these vulnerabilities and for the ones that there are no solutions to, the factor that they are being reported usually means that the Vendor is aware of the vulnerability and in most cases, frantically searching for a patch or update. The vulnerability that was discovered was found in Millennium MP3 Studio. The Millennium MP3 Studio is not the same as all the other MP3 Players for it has many more features. This is an entire studio that allows you to perform a variety of functions. These functions include a studio mix that contains 24 band equalizers, a playlist creator, skin support and much more. The best news of all is that this is completely free and can be downloaded within a few minutes. It is compatible with the majority of operating systems with the inclusion of the Windows Millennium Edition. The files of Windows Millennium Edition include: addreg.exe, agt20.inf, amovie.inf, aol50us.exe as well as applets.inf. This vulnerability occurred because of a boundary error within the processing of the M3U playlist files. It runs the risk of being exploited which will directly result in a stack based buffer overflow attack. This particular stack based buffer overflow occurs when a user is manipulated into opening a file which has been tampered with and contains a large entry. Due to this vulnerability, an attacker could gain access to a system without the permission of the user, which is usually required. This means that the malicious online attacker will have access to the confidential information which you have on your system. This will enable the attacker to commit crimes such as identity theft. This vulnerability was discovered by HACK4LOVE. It was rated as moderately critical and if you are wondering what the solution is for this vulnerability do not despair because I am going to tell you just that. The solution for this vulnerability is for all users of the Mil |
|||||
Software Downloads


lennium MP3 Studio to not open any files which are not trusted with the application. This is very serious and it is highly suggested that users know what the files are and where they come from prior to opening them. This vulnerability has been confirmed in version 1.0 and users need to be aware that other versions may also be at some level of risk. I would thus like to leave you with a quote in conclusion:"It's still basically just solving a puzzle, Years ago, with poor judgment; I was intrigued to break through security on computer systems. Now I do it with the client's permission, for socially acceptable reasons"-Kevin Mitnick
User Comments