BPM STUDIO PRO 4.2 DOS DEVICE PATH VULNERABILITY

From: ][-][UNTER (lopht@tutopia.com)
Date: 02/27/02


From: "][-][UNTER" <lopht@tutopia.com>
To: <bugtraq@securityfocus.com>
Date: Wed, 27 Feb 2002 07:00:39 -0300

Hi Bugtraq !!

BPM STUDIO PRO 4.2 is one of the most famous mp3 mixer and player and it has
an http server implementation for manage the player via the web browser.

Unfortunatly, when you perform a simple http request like:
http://BPM-HOST/con/con
you can crash instantly non-patched Win9x host with a simple Blue Screen !!

HTTP daemon is not activated by default

bye bye

-----------------------------------------------
               ][-][UNTER
Infobyte Security Research Crew
       Buenos Aires, Argentina
-----------------------------------------------



Relevant Pages

  • Re: Embedded WMP with SSL source
    ... player on Mac and/or Firefox when the source URL is https? ... Doesn't happen when the URL is http. ... >>Regards, Ian ...
    (microsoft.public.windowsmedia.player)
  • Re: Complaints about Windows 2000 and Windows Media 9
    ... the player appears to read through the `entries` ... The stream is distributed as ... The player will attempt all the http stream locations first. ... What I'd do really is to set up the mms protocols first in the ASX ...
    (microsoft.public.windowsmedia.player.web)
  • Re: Cant connect to some streams with MP11
    ... their players also support rtsp or http. ... The player will automatically fall back to the second ref stream ... an available server. ...
    (microsoft.public.windowsmedia.player)
  • Re: Konsolenbasierter http-streaming Player?
    ... scheinbar nicht http stream abspielen muss ich Euch hier damit belaestigen. ... Wer weiss welcher Player unter Linux HTTP-Streams in der Konsole abspielen ... HTTP bereitgestellte Datei meinst, dnn geht das. ...
    (de.comp.os.unix.linux.misc)
  • Re: Embedded WMP with SSL source
    ... media player on Mac / Win, ... With the embedded player in Firefox, ... Doesn't happen when the URL is http. ...
    (microsoft.public.windowsmedia.player)