Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
BID:16785
Info
Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 16785 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0720 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2006 12:00AM |
| Updated: | Jun 17 2013 02:47PM |
| Credit: | Discovered by Liu Yexin of NSFocus Security Team and P Robinson. |
| Vulnerable: |
NullSoft Winamp 5.13 NullSoft Winamp 5.12 |
| Not Vulnerable: |
NullSoft Winamp 5.2 |
Discussion
Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
Nullsoft Winamp is prone to a buffer-overflow vulnerability when processing malformed M3U files. The overrun occurs when the M3U playlist is paused or stopped.
This issue is reported to affect Winamp versions 5.12 and 5.13. Earlier versions may also be vulnerable.
Nullsoft Winamp is prone to a buffer-overflow vulnerability when processing malformed M3U files. The overrun occurs when the M3U playlist is paused or stopped.
This issue is reported to affect Winamp versions 5.12 and 5.13. Earlier versions may also be vulnerable.
Exploit / POC
Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
Solution:
This issue has been addressed in Winamp 5.2:
NullSoft Winamp 5.12
NullSoft Winamp 5.13
Solution:
This issue has been addressed in Winamp 5.2:
NullSoft Winamp 5.12
-
NullSoft Winamp 5.2
http://www.winamp.com/player/
NullSoft Winamp 5.13
-
NullSoft Winamp 5.2
http://www.winamp.com/player/
References
Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
References:
References:
- Winamp 5.2 Released (Winamp Forums)
- IRM 018: Winamp 5.13 m3u Playlist Buffer Overflow ("Advisories"
) - NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability (NSFOCUS Security Team
)