First published: Tue Feb 14 2006(Updated: )
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Media Player | =7.1 | |
Microsoft Windows Media Player | =10 | |
Microsoft Windows Media Player | =9 | |
Microsoft Windows 98SE | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows Me | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 98 | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0006 is rated as critical due to its potential for remote code execution.
To remediate CVE-2006-0006, update to the latest version of Microsoft Windows Media Player or install the relevant patches provided by Microsoft.
CVE-2006-0006 affects Microsoft Windows Media Player versions 7.1, 9, and 10.
Yes, CVE-2006-0006 can affect various versions of Windows, including Windows 2000, Windows XP, and Windows 98.
CVE-2006-0006 enables remote attackers to execute arbitrary code via a crafted bitmap file, exploiting a heap-based buffer overflow.