Lucene search

K
nessusTenable5267.PRM
HistoryDec 17, 2009 - 12:00 a.m.

Winamp < 5.57 Multiple Vulnerabilities

2009-12-1700:00:00
Tenable
www.tenable.com
16

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.199

Percentile

96.3%

The remote host is running Winamp, a media player for Windows. The version of Winamp installed on the remote host is earlier than 5.57. Such versions are potentially affected by multiple vulnerabilities :

  • A boundary error in the Module Decoder Plug-in exists when parsing samples and can be exploited to cause a heap-based buffer overflow via a specially crafted β€˜Impulse Tracker’ file. (CVE-2009-3995)

  • An error in the Module Decoder Plug-in when parsing β€˜Ultratracker’ files can be exploited to cause a heap-based buffer overflow. (CVE-2009-3996)

  • An integer overflow error exists in the Module Decoder Plug-in when parsing β€˜Oktalyzer’ files and can be exploited to cause a heap-based buffer overflow.

  • Multiple integer overflow vulnerabilities in the β€˜jpeg.w5s’ and β€˜png.w5s’ filters when processing malformed β€˜JPEG’ and β€˜PNG’ data.

Binary data 5267.prm

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.199

Percentile

96.3%