http://www.eweek.com/article2/0,1759,1749993,00.asp
Its something I already knew about since I had to repair a few faulty MP3,s and noticed the web addresses embedded into the files.
This is the first time I have heard of it being exploited.
Luckily erasing the correct portion negates the digital rights management, as I found out, by using a hex editor.
http://forums.cricketmx.com/viewtopic.php?t=1241
Its something to watch out for


