CVE-2009-4356
Summary
| CVE | CVE-2009-4356 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-18 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (1) JPEG or (2) PNG data in an MP3 file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nullsoft | Winamp | 0.20a | All | All | All |
| Application | Nullsoft | Winamp | 0.92 | All | All | All |
| Application | Nullsoft | Winamp | 1.006 | All | All | All |
| Application | Nullsoft | Winamp | 1.90 | All | All | All |
| Application | Nullsoft | Winamp | 2.0 | All | All | All |
| Application | Nullsoft | Winamp | 2.10 | All | All | All |
| Application | Nullsoft | Winamp | 2.24 | All | All | All |
| Application | Nullsoft | Winamp | 2.4 | All | All | All |
| Application | Nullsoft | Winamp | 2.50 | All | All | All |
| Application | Nullsoft | Winamp | 2.5e | All | All | All |
| Application | Nullsoft | Winamp | 2.6 | All | All | All |
| Application | Nullsoft | Winamp | 2.60 | All | All | All |
| Application | Nullsoft | Winamp | 2.60 | All | full | All |
| Application | Nullsoft | Winamp | 2.60 | All | lite | All |
| Application | Nullsoft | Winamp | 2.61 | All | All | All |
| Application | Nullsoft | Winamp | 2.61 | All | full | All |
| Application | Nullsoft | Winamp | 2.62 | All | All | All |
| Application | Nullsoft | Winamp | 2.62 | All | standard | All |
| Application | Nullsoft | Winamp | 2.64 | All | All | All |
| Application | Nullsoft | Winamp | 2.64 | All | standard | All |
| Application | Nullsoft | Winamp | 2.65 | All | All | All |
| Application | Nullsoft | Winamp | 2.6x | All | All | All |
| Application | Nullsoft | Winamp | 2.70 | All | All | All |
| Application | Nullsoft | Winamp | 2.70 | All | full | All |
| Application | Nullsoft | Winamp | 2.71 | All | All | All |
| Application | Nullsoft | Winamp | 2.72 | All | All | All |
| Application | Nullsoft | Winamp | 2.73 | All | All | All |
| Application | Nullsoft | Winamp | 2.73 | All | full | All |
| Application | Nullsoft | Winamp | 2.74 | All | All | All |
| Application | Nullsoft | Winamp | 2.75 | All | All | All |
| Application | Nullsoft | Winamp | 2.76 | All | All | All |
| Application | Nullsoft | Winamp | 2.77 | All | All | All |
| Application | Nullsoft | Winamp | 2.78 | All | All | All |
| Application | Nullsoft | Winamp | 2.79 | All | All | All |
| Application | Nullsoft | Winamp | 2.7x | All | All | All |
| Application | Nullsoft | Winamp | 2.80 | All | All | All |
| Application | Nullsoft | Winamp | 2.81 | All | All | All |
| Application | Nullsoft | Winamp | 2.9 | All | All | All |
| Application | Nullsoft | Winamp | 2.90 | All | All | All |
| Application | Nullsoft | Winamp | 2.91 | All | All | All |
| Application | Nullsoft | Winamp | 2.92 | All | All | All |
| Application | Nullsoft | Winamp | 2.95 | All | All | All |
| Application | Nullsoft | Winamp | 3.0 | All | All | All |
| Application | Nullsoft | Winamp | 3.1 | All | All | All |
| Application | Nullsoft | Winamp | 5.0 | All | All | All |
| Application | Nullsoft | Winamp | 5.0.1 | All | All | All |
| Application | Nullsoft | Winamp | 5.0.2 | All | All | All |
| Application | Nullsoft | Winamp | 5.01 | All | All | All |
| Application | Nullsoft | Winamp | 5.02 | All | All | All |
| Application | Nullsoft | Winamp | 5.03 | All | All | All |
| Application | Nullsoft | Winamp | 5.03a | All | All | All |
| Application | Nullsoft | Winamp | 5.04 | All | All | All |
| Application | Nullsoft | Winamp | 5.05 | All | All | All |
| Application | Nullsoft | Winamp | 5.06 | All | All | All |
| Application | Nullsoft | Winamp | 5.07 | All | All | All |
| Application | Nullsoft | Winamp | 5.08 | All | All | All |
| Application | Nullsoft | Winamp | 5.08 | c | All | All |
| Application | Nullsoft | Winamp | 5.08 | d | All | All |
| Application | Nullsoft | Winamp | 5.08 | e | All | All |
| Application | Nullsoft | Winamp | 5.08c | All | All | All |
| Application | Nullsoft | Winamp | 5.08d | All | All | All |
| Application | Nullsoft | Winamp | 5.08e | All | All | All |
| Application | Nullsoft | Winamp | 5.09 | All | All | All |
| Application | Nullsoft | Winamp | 5.091 | All | All | All |
| Application | Nullsoft | Winamp | 5.093 | All | All | All |
| Application | Nullsoft | Winamp | 5.094 | All | All | All |
| Application | Nullsoft | Winamp | 5.1 | All | All | All |
| Application | Nullsoft | Winamp | 5.1 | - | surround | All |
| Application | Nullsoft | Winamp | 5.11 | All | All | All |
| Application | Nullsoft | Winamp | 5.111 | All | All | All |
| Application | Nullsoft | Winamp | 5.112 | All | All | All |
| Application | Nullsoft | Winamp | 5.12 | All | All | All |
| Application | Nullsoft | Winamp | 5.13 | All | All | All |
| Application | Nullsoft | Winamp | 5.2 | All | All | All |
| Application | Nullsoft | Winamp | 5.21 | All | All | All |
| Application | Nullsoft | Winamp | 5.22 | All | All | All |
| Application | Nullsoft | Winamp | 5.23 | All | All | All |
| Application | Nullsoft | Winamp | 5.24 | All | All | All |
| Application | Nullsoft | Winamp | 5.3 | All | All | All |
| Application | Nullsoft | Winamp | 5.31 | All | All | All |
| Application | Nullsoft | Winamp | 5.32 | All | All | All |
| Application | Nullsoft | Winamp | 5.33 | All | All | All |
| Application | Nullsoft | Winamp | 5.34 | All | All | All |
| Application | Nullsoft | Winamp | 5.35 | All | All | All |
| Application | Nullsoft | Winamp | 5.36 | All | All | All |
| Application | Nullsoft | Winamp | 5.5 | All | All | All |
| Application | Nullsoft | Winamp | 5.51 | All | All | All |
| Application | Nullsoft | Winamp | 5.52 | All | All | All |
| Application | Nullsoft | Winamp | 5.53 | All | All | All |
| Application | Nullsoft | Winamp | 5.531 | All | All | All |
| Application | Nullsoft | Winamp | 5.54 | All | All | All |
| Application | Nullsoft | Winamp | 5.541 | All | All | All |
| Application | Nullsoft | Winamp | 5.55 | All | All | All |
| Application | Nullsoft | Winamp | 5.551 | All | All | All |
| Application | Nullsoft | Winamp | 5.552 | All | All | All |
| Application | Nullsoft | Winamp | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Exploit, Vendor Advisory |
| Winamp JPEG and PNG Multiple Integer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| WINAMP.COM | Forums - Winamp 5.572 Released (5.57 Revised, Build 2830) | af854a3a-2127-422b-91ae-364da2661108 | forums.winamp.com | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.