Lucene search

K
saintSAINT CorporationSAINT:3CBC2A496A0FD50874A12950CA305D38
HistoryJan 31, 2006 - 12:00 a.m.

Winamp playlist file buffer overflow

2006-01-3100:00:00
SAINT Corporation
my.saintcorporation.com
26

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.776

Percentile

98.2%

Added: 01/31/2006
CVE: CVE-2006-0476
BID: 16410
OSVDB: 22789

Background

Winamp is a media player for Windows.

Problem

A buffer overflow in Winamp allows code execution when a specially crafted playlist file is opened.

Resolution

Upgrade to Winamp 5.13 or higher.

References

<http://secunia.com/advisories/18649/&gt;

Limitations

Exploit requires user to choose Play -> File from the Winamp menu and enter the exploit URL. Exploit works on Winamp 5.12.

Platforms

Windows

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.776

Percentile

98.2%