xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Microsoft Windows XP WMA/MP3属性缓冲区溢出漏洞


发布时间:2002-12-18
更新时间:2002-12-18
严重程度:
威胁程度:远程管理员权限
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:6427
CVE(CAN) ID:CAN-2002-1327

受影响系统
Microsoft Windows XP
   +Microsoft Windows XP Home
   +Microsoft Windows XP Professional
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP Home SP1
Microsoft Windows XP Home
Microsoft Windows XP Professional SP1
Microsoft Windows XP Professional
详细描述
Windows XP在处理恶意属性的MP3/WMA (Windows Media) 格式文件存在一个缓冲区溢出漏洞。

攻击者可能可以利用这个漏洞在目标系统执行任意代码。

解决方案
Microsoft Windows XP Home SP1:
     Microsoft Patch Q329390
     http://microsoft.com/downloads/details.aspx?FamilyId=A0BE7AF2-2653-4767-A85D-24BF68D28D20&displaylang=en
Microsoft Windows XP Professional SP1:
     Microsoft Patch Q329390
     http://microsoft.com/downloads/details.aspx?FamilyId=A0BE7AF2-2653-4767-A85D-24BF68D28D20&displaylang=en
Microsoft Windows XP 64-bit Edition SP1:
     Microsoft Patch Q329390
     http://microsoft.com/downloads/details.aspx?FamilyId=FBA972FB-FF2A-41D0-8745-D31EEFB90437&displaylang=en
Microsoft Windows XP :
Microsoft Windows XP Professional :
     Microsoft Patch Q329390
     http://microsoft.com/downloads/details.aspx?FamilyId=A0BE7AF2-2653-4767-A85D-24BF68D28D20&displaylang=en
Microsoft Windows XP Home :
     Microsoft Patch Q329390
     http://microsoft.com/downloads/details.aspx?FamilyId=A0BE7AF2-2653-4767-A85D-24BF68D28D20&displaylang=en
Microsoft Windows XP 64-bit Edition :
     Microsoft Patch Q329390
     http://microsoft.com/downloads/details.aspx?FamilyId=FBA972FB-FF2A-41D0-8745-D31EEFB90437&displaylang=en

相关信息
发现者:Tony Bettini
相关资料:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-072.asp