Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-1325

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2004-1325
Last Modified 05 Sep 2008 04:41:00
Published 18 Dec 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-1325

Summary

The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.

Vulnerable Systems

Application

  • Microsoft Windows Media Player 9


References

XF - mediaplayer-activex-information-disclosure(18587)

BID - 12032

BUGTRAQ - 20041218 MS Windows Media Player 9 Vulns (2)


Last Updated: 27 May 2016 10:38:59