20070310 Windows Multimedia mmioRead Denial of Service Vulnerabilitymailing list
http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0063.html CVE-2007-1492
Microsoft Windows XP/2000 - 'WinMM.dll' / '.WAV' Remote Denial of Service
Record summary
CVE-2007-1492 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.
Description
winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows XP/2000 - 'WinMM.dll' / '.WAV' Remote Denial of ServiceExploitDB exploitby Michal MajchrowiczNot analyzed1 file
References
434101vdb entry
http://osvdb.org/34101 22938vdb entry
http://www.securityfocus.com/bid/22938 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-1492