PT-2006-7203 · Microsoft · Windows Media Player

Steven M. Christey

·

Published

2006-12-15

·

Updated

2018-10-17

·

CVE-2006-6601

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Windows Media Player version 10.00.00.4036
Description The issue allows remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks. This could involve the number of tracks or time division fields that are set to 0.
Recommendations For Windows Media Player version 10.00.00.4036, consider avoiding the use of .MID files with malformed header chunks until a fix is available. As a temporary workaround, restrict the handling of MIDI files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-6601

Affected Products

Windows Media Player