Microsoft: Upgrade Your Media Player
By David Worthington | Published May 24, 2001, 5:05 AM
In the company's seventh security bulletin this month, Microsoft has announced two vulnerabilities affecting Windows Media Player 6.4 and 7.0. Users of Windows Media Player 6.4 can download one patch with fixes for both exploits, however a heftier download is needed in order to patch version 7.0. Microsoft recommends that Windows Media Player 7.0 users upgrade to the newest release, 7.1.
In both cases, information must be known about the user's system in order for an attacker to successfully exploit these flaws. Privacy is enhanced when users of Windows Media Player uncheck the option: "Allow Internet sites to uniquely identify your player."
The first issue is a regression of an earlier buffer overrun. This variation of the previous flaw affects code that processes Active Stream Redirector (ASX) files. The component contains an unchecked buffer that can become overwhelmed and allow malicious users to execute the code of their choice on a target machine. According to Microsoft, ASX files allow streaming media to be played from Internet and Intranet sites, and enable the use of playlists.
A second threat stems from the default behavior when Windows Media Player handles Internet shortcuts. These shortcuts are saved to the 'Temporary Files' folder on a system with fixed names. This action changes the Security Zone from Internet to Local Computer Zone, thus allowing greater access to system resources. In Windows 9x and ME, these temporary folders are in a default location for all users. This flaw will allow certain files on a user's hard drive to be read, but not modified or deleted. The attacker would also need to know the exact name of a file in order to obtain access.
Windows Media Player 6.4 users may download a patch for the player, and those running 7.0 should upgrade to version 7.1. For more information the security flaws, visit Microsoft TechNet Security.
WMP 7.1 allows for ad streaming. Who wants that. I think M$ is just tricking people to upgrade to allow for ad streaming. The more people using 7.1 or higher, the more advertisers M$ can sign up. Just uncheck "Allow Internet sites to uniquely identify your player" in Tools/Options.
Score: 0
|VCD not DVD, different MPEG encoding.
However having said that WMP should be able to play a VD without any troubles (I'll give it a go through Win2K tonight). I've always used PowerDVD for video.
Score: 0
|It should play DVD's. Now do you have a decoder card or did you actually think that MS was giving away a free DVD software decoder?
Score: 0
|did you even read his question? VCD!!!!!! NOT DVD!!!! and my media player plays .dat in win2k, but i'm using 6.4. if i remember correctly though, version 7 played them too in that brief stint that i checked out that crap version 7.
Score: 0
|Yes thanks, my question is VCD not DVD. As I remember I can play .DAT file in version 7 but after upgrade to 7.1, it cannot play anymore. May be some codec haven't installed, is it ?? I can play .DAT in version 7.1 under Win Me but not under W2K pro.
Score: 0
|Yes, I now i saw VCD!!! I was refering to WMP not being a software DVD decoder. You need the hardware to play DVD's through WMP.
Score: 0
|I think you can get the codec somewhere online... look up DVD decoding, they have th Codecs for playing
Dave
Score: 0
|I have problems using 7.1 version under W2K pro to play .DAT file (directly from the VCD) but it is ok in Win Me.
Any idea ?
Score: 0
|listen ok ... i Love the fact that linux is Stable ... but i also love Microsoft's GUI ... ok ok ok i know what you're thinking ... it might be unstable and crash a lot .. but as a GUI it ROCKS ... amd that's why people use windows over linux .. now ... take KDE and GNOME and look at them ... you're gonan tell me they're as user-friendly and simple as the windows gui? .. start menu, a couple od quicklinks a taskbar and a system tray .. now THATS a gui ... not 6 million icons showing you cpu usage and stuf .. i mean i know its good to have and it would be cool to be able to add these things .. but for the general population how may of us care how much cpu usage we use up .. i mean cmon id rather have my 5% of desktop space back thank you very much ... i mean i tried linux ... and the one turn off i had with is is the GUI ... the windows GUI (windows 2000 and windows XP ala plain vanilla setting) is head over heels better than KDE and/or GNOME...
now here's what i tell you ... build a freakin gui on linux that is like the windows gui and then and only then will linux appeal to the masss market ... once we get that done then we could try and improve upon it by gettting user feedback etc.
so my cry out to the open source world has been made ... now gather yourselves up and lets get the ball rolling for crying out loud ... KDE and GNOME will NOT take us there ...
please post your feedback.
Score: 0
|This already exists in numerous forms. Linux on the desktop doesn't work because it's too complicated to setup and maintain by people's mothers, not because of what it looks like.
Score: 0
|Linux is a stable Server OS, not desktop. It wasn't really designed with the Desktop user in mind. Just to be not bias I am actually installing Redhat 7.1 on one of my boxes at work. I work at Microsoft. Now I see I made you laugh. I've always been a redhat fan actually. Lets think why this might be.... maybe because ms sucked pre 2k. Now I'm a big supporter of MS, but Linux, Redhat, Mandrake kinda let me down. They are begining to destabalize because they want third party to fix all there problems. For those who haven't noticed, Netscape suffered the same issue with the release of NS6.
Actually, what I am really happy about is that MS offers a lot of features, which means less third party installs, more stable. The reason that MS usually crashes is third party software or bad hardware. Besides quit buying hardware made by little kids in Taiwan. Read compatability lists. There are even lists out there for known good configuration computer systems.
As a last note, Media player depends a lot on your hardware for certain things, so if something doesn't work. ITS YOUR FAULT!!!
Score: 0
|come on, Windows is NOT UNSTABLE!!!
atleast not my system, firstly, if you have a crappy system bought from like, Hewlett Packard, or anyother, pre-built system.
then you can keep Linux if you wish...
the best is to build your own system, with expensive quality parts.
and second, don't buy Intel, they suck horse balls. an AMD is the system to have, i have maybe one system crash a month, the most recent one, was because of overheating, my cpu fan was broken.
I use Win2k btw...
Score: 0
|I agree. I love Linux and all (I use Debian on a Pentium 75 as an IP masq. box) but it just wasn't meant to be used as a desktop system.
It's like running a webserver on Windows '95. Sure, it'll work, and it'll get small jobs done. But it'll really suck.
I've switched to Windows 2000 Professional, and so far I've been fairly impressed.
Score: 0
|this guy is right
if you get a cheap HP system (believe me HP is cheap, I have two of them and they really suck), or a stupid COMPAQ system your computer is gonna be as stable as a toothpick on ice
but if you re-format VOILA!!
all your problems are gone (so are your files he he)
Score: 0
|Yer,NUTS you probably tweaked the machines so much, that only GOD could make them run! I've been running HP'S for three years and they work perfect, no crashes, nuttin!, WAKE UP
Score: 0
|I think I know how you feel. I hated GNOME on Redhat, its just clunky, slow, and plain messy. But I've been running KDE2 on RH and Mandrake, and its a LOT better. Its really much more windows-like, cleaner, faster, and the keyboard mappings are already similar (i.e. ALT+F4, windows key).
Score: 0
|windows media player 7 seems to not play nice with my computer, which is why i havent upgraded to it. every time i install it (ive even tried 7.1) upon rebooting, when i try to run WMP, the program freezes up and the whole computer just runs sluggishly while this frozen window is open. i usually just uninstall, reboot and then check the event log for any weirdness that may have been noted - nothing. so maybe 7.2 or whatever will work with my system.
naturally im not saying EVERYONE's windows2k system will have problems, this is obvioulsy not the case... if anyone knows why this may happen feel free to let me know!
Score: 0
|Just a thought.....when you went to install WMP 7.1, did you choose the "Update" or "Reinstall" option? If you picked reinstall then I'm not sure what might be going on with your system, however if you chose update then that might be the problem right there.
Score: 0
|Microsoft produces the worst products that I have ever tested. This is 2001 and things are supposed to be better. WMP is supposed to be a smaller file and a much faster software but microsoft always make products that are ass-backwards. For god's sake how can you go from good to bad and then advertise it to the world.
Score: 0
|The update is too big to download..it's just like downloading a new WMP 7. Is this what you call an update or patch...dang~ kick their asses.
Score: 0
|I have a Pentium 200mmx, 64ram, Voodoo 5 5500 PCI and with both hard drives combined, a total of 7gigs. Pretty s***ty specs mostly, besides the Voodoo and it only takes me about 5-10seconds to load WMP7.1. And I think WMP6.4 is great, cuz it's fast & runs practically everything. But for any audio, I DEFINITELY DO NOT use WMP - I use Winamp:) Even though my CPU is REALLY old, it's surprising quick... I know people who have 400mhz and my benchmark isn't that far off of theirs, but maybe that's cuz of their motherboard or whatever...
Score: 0
|Unless you are doing some heavy development or running some high requirement games, your computer is probably perfect for what you need. I think it is stupid how some people blow there money on all this "up-to-date" hardware and don't even use it. I am one of those people that do blow my money, however, I put my hardware to work!!! :)
Score: 0
|Yet another reason I Use WinAmp for my Multimedia, not to mention Media Plaer (Like 90% of all other MS software) is Bloat ware - it takes a good 1-2 minutes for Media Player to load On My Pentium II (Celeron) 500 MHZ ! now that's bloat ware.
Not to mention that it need's to configure itself for the internet.
WinAmp- It really kicks the llamas a** ! & Bill's too.
Score: 0
|Another Oxymoron
You use Winamp to player movie files eh? I bet you drink oil when you are thirsty, dont you?. Read: Windows Media Player is not just a Mp3 Player, dont be such a smart ass. Sorry if i offended anyone, just grow up and stop jumping into conclusions.
Score: 0
|I'm almost sure you didn't hear about plug-ins.
Score: 0
|And I'm sure you have no idea how those plugins work - they just use WMP to play the movies in their window.
Score: 0
|Actually, one of the more successful video plug-ins for winamp, Tara, uses Real Player as a backbone.
Score: 0
|1-2 minutes to start up????? Are you running some huge process in the background? Is your computer set up THAT poorly? I'm just curious because after all the reports from everyone here on how slow WMP is, I installed WMP 7.1 and on my system (P3-500) is loads up in a few seconds - fast enough not to be noticed. Seeing as a lot of people have systems that are much faster than mine I'm really suprised that it's so slow for them. But 1-2 minutes is ridiculous! How long does it take your computer to start up?
Score: 0
|No it's just Media Player Bloating my system.
everything else is quick.
Score: 0
|No it's just Media Player Bloating my system.
everything else is quick.
Score: 0
|No it's just Media Player Bloating my system.
everything else is quick.
Score: 0
|Actually I Have Yet to find a decent Video Media Player...
Winamp play *ALMOST* every type of audio format, the only exceptions I found are au, & ra.
I personally don't know of any others.
Score: 0
|you don't/didn't like PowerDVD as a Video Player?
Score: 0
|oh gawd
RealPlayer sucks more than WMP has EVER sucked, in ANY version
Real will be going under very soon, because like their software, their company sucks
Score: 0
|do spwolf is huge?
Score: 0
|Dam!!! 1-2mins. Thats kinda long. Takes me bout 2-3secs
Score: 0
|