>> Microsoft Windows Media Player MIDI File Format Handling Denial of Service Vulnerability
Title : Microsoft Windows Media Player MIDI File Format Handling Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-5039 CVE ID : CVE-2006-6601 - CVE-2006-6602
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-17
Technical Description
A vulnerabilitiy has been identified in Microsoft Windows Media Player, which could be exploited by attackers to cause a denial of service. This issue is due to a division by zero error when handling a specially crafted MIDI file with a header chunk containing malformed fields (i.e. number of tracks and delta time), which could be exploited by attackers to crash a vulnerable application via a specially crafted file.