Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
BID:16410
Info
Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 16410 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0476 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2006 12:00AM |
| Updated: | Nov 02 2007 04:26PM |
| Credit: | Discovered by ATmaCA. iDefense reports that this issue was independently discovered by Alan Mccaig (b0f) <[email protected]> and Ruben Santamarta <[email protected]> as well. |
| Vulnerable: |
NullSoft Winamp 5.12 NullSoft Winamp 5.11 |
| Not Vulnerable: |
NullSoft Winamp 5.13 |
Discussion
Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
Winamp is susceptible to a buffer-overflow vulnerability when handling specially crafted playlist files.
An attacker may exploit this issue to gain unauthorized access to a computer with the privileges of the user that activated the vulnerable application.
Winamp 5.11 and 5.12 are reportedly affected by this issue.
Winamp is susceptible to a buffer-overflow vulnerability when handling specially crafted playlist files.
An attacker may exploit this issue to gain unauthorized access to a computer with the privileges of the user that activated the vulnerable application.
Winamp 5.11 and 5.12 are reportedly affected by this issue.
Exploit / POC
Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
Exploit code is available.
http://www.securityfocus.com/data/vulnerabilities/exploits/winamp0day.c
Exploit code 'winamp_playlist_unc.pm' has been released as part of the Metasploit framework.
http://www.securityfocus.com/data/vulnerabilities/exploits/winamp_playlist_unc.pm
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code is available.
http://www.securityfocus.com/data/vulnerabilities/exploits/winamp0day.c
Exploit code 'winamp_playlist_unc.pm' has been released as part of the Metasploit framework.
http://www.securityfocus.com/data/vulnerabilities/exploits/winamp_playlist_unc.pm
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
Solution:
The vendor has released version 5.13 to address this issue.
Solution:
The vendor has released version 5.13 to address this issue.
References
Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
References:
References:
- Fixed: [in_mp3] Critical security flaw fixed. (Winamp)
- Technical Cyber Security Alert TA06-032A (US-CERT)
- VU#604745 - Winamp fails to properly handle playlists with long "file" parameter (US-CERT)
- Winamp Home Page (NullSoft)
- iDefense Security Advisory 02.01.06: Winamp m3u Parsing Stack Overflow Vulnerabi ("[email protected]"
) - Re: Winamp 5.12 - 0day exploit - code execution through playlist (Chris Wysopal
) - Winamp 5.12 - 0day exploit - code execution through playlist (Process
)