New vulnerability in this video player

Aug 24, 2007 13:55 GMT  ·  By

Media Player Classic is often regarded as a simple alternative for the more-advanced Windows Media Player that provides excellent functionality for most video formats. Numerous consumers are currently using Media Player Classic since it requires a very low amount of resources but offers very good features for an open-source application. But sometimes, this player might become a real threat for your computer due to a simple vulnerability discovered in its engine. Security company Secunia rated the flaw as highly-critical and said that it affects Media Player Classic 6.x and more exactly, the 6.4.9.0 release. However, other versions might be also affected so keep an eye on the security notifications that are released these days.

"wushi has discovered a vulnerability in Media Player Classic, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error when processing .FLI files and can be exploited to cause a buffer overflow when a user e.g. is tricked into opening a malicious FLI file. Successful exploitation allows execution of arbitrary code," Secunia wrote in the advisory.

At this time, there is only a single solution to avoid the successful exploitation of the vulnerability: avoid opening untrusted .FLI formats because this is the only way to take advantage of the security flaw.

As you can see, even a simple video player can sometimes harm your computer and invite hackers to view the private information stored on your hard drive. It was proved once again that no matter what security solution you install on the computer, a simple security hole discovered in one of the applications running on your system can compromise the entire protection and make it accessible from anywhere on the web.

Media Player Classic is available for download on Softpedia.