Closed Bug 259272 Opened 21 years ago Closed 21 years ago

.asf files can execute any files on the computer with windows media player and chm

Categories

(Firefox :: File Handling, defect)

x86
Windows XP
defect
Not set
critical

Tracking

()

VERIFIED INVALID

People

(Reporter: korn, Assigned: bugs)

Details

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3 .ASF (Avanced Streaming File) can execute a .html file in the Windows Media Player which activates the .chm components which allow's everybody to install a file on his computer Reproducible: Didn't try Steps to Reproduce: 1. 2. 3. there already has been a worm called "Manymize.A" it does use the .asf exploit to install the worm on computers. i found a link a while ago which used the .asf exploit too, and see, it worked! the windows media player was opened and the program was in my task manager
This is a vulnerability in Windows, and it's not something that Firefox can prevent. Certainly, it's not a Firefox security issue. The virus exploits a flaw in WMP (which was patched a *long* time ago, circa 2001) whereby WMP allows itself to run external executable content via a CHM file. There is nothing we can (or should) do about this. Reference: http://vil.nai.com/vil/content/v_99587.htm mconnor, can you please verify my resolution?
Status: UNCONFIRMED → RESOLVED
Closed: 21 years ago
Resolution: --- → INVALID
yes, this is something that we can't really do anything about. The vast majority of asf files aren't bogus, and the WMP vuln was fixed a long time ago, so its not like its this giant hole that we should try to protect unknowning users against by somehow blacklisting .asf
Status: RESOLVED → VERIFIED
Removing confidential flag from bugs resolved INVALID
Group: security
You need to log in before you can comment on or make changes to this bug.