Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow Vulnerability
BID:12381
Info
Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 12381 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1150 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Yu Yang of NSFOCUS Security Team is credited with the discovery of this issue. |
| Vulnerable: |
NullSoft Winamp 5.0 8 NullSoft Winamp 5.0 7 NullSoft Winamp 5.0 6 NullSoft Winamp 5.0 5 NullSoft Winamp 5.0 4 NullSoft Winamp 5.0 3 NullSoft Winamp 5.0 2 NullSoft Winamp 5.0 1 |
| Not Vulnerable: |
NullSoft Winamp 5.0 8c |
Discussion
Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects the IN_CDDA.dll library of Nullsoft's Winamp. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers. It should be noted that this issue is not related to the issue outlined in BID 11730 (Nullsoft Winamp IN_CDDA.dll Remote Buffer Overflow Vulnerability).
This issue will facilitate remote exploitation as an attacker may distribute malicious play-list files and entice unsuspecting users to process them with the affected application.
It should be noted that this issue was originally reported in BID 12245 (Nullsoft Winamp Multiple Unspecified Vulnerabilities). It has been assigned a new BID due to the release of more information.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application.
A remote buffer overflow vulnerability affects the IN_CDDA.dll library of Nullsoft's Winamp. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers. It should be noted that this issue is not related to the issue outlined in BID 11730 (Nullsoft Winamp IN_CDDA.dll Remote Buffer Overflow Vulnerability).
This issue will facilitate remote exploitation as an attacker may distribute malicious play-list files and entice unsuspecting users to process them with the affected application.
It should be noted that this issue was originally reported in BID 12245 (Nullsoft Winamp Multiple Unspecified Vulnerabilities). It has been assigned a new BID due to the release of more information.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application.
Exploit / POC
Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow Vulnerability
A proof of concept exploit (Winamp_POC_M3U) that is designed to spawn a local command shell has been supplied by Rojodos <rojo2_bugtraqyahoo.es>:
A proof of concept exploit (Winamp_POC_M3U) that is designed to spawn a local command shell has been supplied by Rojodos <rojo2_bugtraqyahoo.es>:
Solution / Fix
Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
NullSoft Winamp 5.0 1
NullSoft Winamp 5.0 8
NullSoft Winamp 5.0 5
NullSoft Winamp 5.0 2
NullSoft Winamp 5.0 6
NullSoft Winamp 5.0 3
NullSoft Winamp 5.0 7
NullSoft Winamp 5.0 4
Solution:
The vendor has released an upgrade dealing with this issue.
NullSoft Winamp 5.0 1
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 8
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 5
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 2
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 6
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 3
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 7
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
NullSoft Winamp 5.0 4
-
Nullsoft Winamp 5.08c
http://forums.winamp.com/showthread.php?s=&threadid=202799
References
Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow Vulnerability
References:
References:
- Winamp 5.08c released (Nullsoft)
- Winamp Home Page (NullSoft)
- NSFOCUS SA2005-01 : Buffer Overflow in WinAMP in_cdda.dll CDA Device Name (NSFOCUS Security Team
)