Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share
  • icon

Vulnerability Found In MP3 And Windows Media Files


Flaw can let an attacker take over a user's PC if the user lets mouse hover over an infected file.



Security experts are warning of a vulnerability in MP3 and Windows Media files that can be activated simply by a user hovering a mouse over an infected file. The vulnerability could let attackers take over a user's PC.

The flaw in Windows XP can force the operating system to run code when a music file is played by Windows Explorer, the operating system's file-browsing application. Hovering the mouse pointer over a file will open a preview of it and trigger the file's payload, if it has one. The vulnerability doesn't affect Windows Media Player, Microsoft says.


More Software Insights

White Papers

Webcasts

Reports

Videos


A 30-second description by CEO David Fox of Agistix, a vendor founded in 2003 that focuses on logistics and supply chain management software as a service. Agistix, according to Fox, helps customers Going green often involves the immediate thought of taming the data center, but there's plenty to do in software as well: Everything from using collaboration tools, to process automation, to monitoring your energy footprint. We talked to IBM/Tivoli Software CTO Alan Ganek and InformationWeek's head of analytics, Art Wittmann, about some of the latest trends in going green. Spiceworks agentless, ad-supported management tool runs right in the browser, targeted at the small to medium sized business.
Spiceworks agentless, ad-supported management tool runs right in the browser, targeted at the small to medium sized business.
The popular Nullsoft Winamp free media player is also vulnerable.

Further information and patches to Windows and Winamp are available in several places on the Web: the CERT Coordination Center at Carnegie Mellon University; Foundstone, with advisories for both Windows XP and Winamp; Microsoft; and Nullsoft, which has an update to Winamp.


Subscribe to RSS


Advertisement


CAREER CENTER
Ready to take that job and shove it?



TechCareers

SEARCH
Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.





Subscription Info
Apply for a free 52-week subscription to InformationWeek (a $199 value)

Last Name:

First Name:

Title:

Company Name:

City:

Business Address:

Zip:

State:

Email Address:

NOTE: Offer valid for U.S., U.S. possessions, & Canada only