Vulnerability Name: | CVE-2008-5745 (CCN-47664) | ||||||||
Assigned: | 2008-12-24 | ||||||||
Published: | 2008-12-24 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. Note: this has been incorrectly reported as a code-execution vulnerability. Note: it is not clear whether this issue is related to CVE-2008-4927. This bug cannot be leveraged for code execution according to the vendor. Source 1 - http://blogs.technet.com/swi/archive/2008/12/29/windows-media-player-crash-not-exploitable-for-code-execution.aspx Source 2 - http://blogs.technet.com/msrc/archive/2008/12/29/questions-about-vulnerability-claim-in-windows-media-player.aspx | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-189 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Dec 24 2008 - 17:32:58 CST MS Windows Media Player * (.WAV) Remote Integrer Overflow Source: CCN Type: The Microsoft Security Response Center (MSRC) Blog, Monday, December 29, 2008 12:02 PM Questions about Vulnerability Claim in Windows Media Player Source: CCN Type: Security Vulnerability Research & Defense Blog, December 29, 2008 12:40 PM Windows Media Player crash not exploitable for code execution Source: MITRE Type: CNA CVE-2008-5745 Source: SREASON Type: UNKNOWN 4823 Source: CCN Type: SECTRACK ID: 1021495 Windows Media Player Integer Overflow in Playing WAV Files Lets Remote Users Deny Service Source: CCN Type: Microsoft Windows Media Player Web site Microsoft Windows Media Player Source: BUGTRAQ Type: UNKNOWN 20081224 MS Windows Media Player * (.WAV) Remote Integrer Overflow Source: BID Type: Exploit 33018 Source: CCN Type: BID-33018 RETIRED: Microsoft Windows Media Player WAV/MID/SND File Parsing Integer Overflow Vulnerability Source: CCN Type: BID-34534 RETIRED: Microsoft Windows Media Player MID File Parsing Integer Overflow Vulnerability Source: CCN Type: BID-34585 Microsoft Windows Media Player MIDI File Denial of Service Vulnerability Source: CCN Type: BID-34587 Microsoft Windows Media Player WAV File Multiple Denial of Service Vulnerabilities Source: SECTRACK Type: UNKNOWN 1021495 Source: XF Type: UNKNOWN win-mediaplayer-wav-snd-mid-dos(47664) Source: XF Type: UNKNOWN win-mediaplayer-wav-snd-mid-dos(47664) Source: EXPLOIT-DB Type: UNKNOWN 7585 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |