First published: Fri Dec 15 2006(Updated: )
Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Windows Media Player | =10.00.00.4036 | |
Microsoft Windows XP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6601 has been classified as a moderate severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2006-6601, users should update Windows Media Player to the latest version available.
CVE-2006-6601 vulnerabilities can be exploited by remote attackers through specially crafted MIDI files.
CVE-2006-6601 affects Windows Media Player version 10.00.00.4036 and Microsoft Windows XP SP2.
Yes, user interaction is required for the exploit as the attacker must cause the victim to open the malicious MIDI file.