Nullsoft Winamp Malformed ID3v2 Tag Buffer Overflow Vulnerability
BID:14276
Info
Nullsoft Winamp Malformed ID3v2 Tag Buffer Overflow Vulnerability
| Bugtraq ID: | 14276 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2005 12:00AM |
| Updated: | Jul 15 2005 12:00AM |
| Credit: | Leon Juranic <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
NullSoft Winamp 5.0 91 NullSoft Winamp 5.0 9 NullSoft Winamp 5.0 3a |
| Not Vulnerable: | |
Discussion
Nullsoft Winamp Malformed ID3v2 Tag Buffer Overflow Vulnerability
Winamp is susceptible to a buffer overflow vulnerability in its ID3v2 functionality. This issue is due to a failure of the application to properly bounds check input data prior to copying it into a fixed size memory buffer.
This issue will facilitate remote exploitation as an attacker may distribute malicious MP3 files and entice unsuspecting users to process them with the affected application.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application.
Versions 5.03a, 5.09, and 5.091 are reported vulnerable to this issue. Other versions are also likely affected.
Winamp is susceptible to a buffer overflow vulnerability in its ID3v2 functionality. This issue is due to a failure of the application to properly bounds check input data prior to copying it into a fixed size memory buffer.
This issue will facilitate remote exploitation as an attacker may distribute malicious MP3 files and entice unsuspecting users to process them with the affected application.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application.
Versions 5.03a, 5.09, and 5.091 are reported vulnerable to this issue. Other versions are also likely affected.
Exploit / POC
Nullsoft Winamp Malformed ID3v2 Tag Buffer Overflow Vulnerability
A proof of concept MP3 file has been provided by Leon Juranic <[email protected]>. Symantec has not verified the safety of the file, and recommends extreme caution when examining it.
A proof of concept MP3 file has been provided by Leon Juranic <[email protected]>. Symantec has not verified the safety of the file, and recommends extreme caution when examining it.
Solution / Fix
Nullsoft Winamp Malformed ID3v2 Tag Buffer Overflow Vulnerability
Solution:
Reportedly, this issue has been addressed in the latest release of Winamp. Symantec was not able to verify this information. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, this issue has been addressed in the latest release of Winamp. Symantec was not able to verify this information. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nullsoft Winamp Malformed ID3v2 Tag Buffer Overflow Vulnerability
References:
References: