Nullsoft Winamp AIP Buffer Overflow Vulnerability
BID:2680
Info
Nullsoft Winamp AIP Buffer Overflow Vulnerability
| Bugtraq ID: | 2680 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2001 12:00AM |
| Updated: | Apr 29 2001 12:00AM |
| Credit: | Reported to bugtraq by <[email protected]>) on April 29, 2001. |
| Vulnerable: |
NullSoft Winamp 2.73 (full) NullSoft Winamp 2.72 NullSoft Winamp 2.71 NullSoft Winamp 2.70 (full) NullSoft Winamp 2.65 NullSoft Winamp 2.64 (standard) NullSoft Winamp 2.62 (standard) NullSoft Winamp 2.61 (full) NullSoft Winamp 2.60 (lite) NullSoft Winamp 2.60 (full) |
| Not Vulnerable: |
NullSoft Winamp 2.74 NullSoft Winamp 2.50 NullSoft Winamp 2.24 NullSoft Winamp 2.5 e NullSoft Winamp 2.4 |
Discussion
Nullsoft Winamp AIP Buffer Overflow Vulnerability
Winamp is a popular media player supporting MP3 and other filetypes.
Versions of Winamp are vulnerable to a buffer overflow condition triggered during processing of Audiosoft parameter files (*.AIP).
A user may insert a large sequence of characters into an *.AIP file. When parsed by Winamp, the data will cause a stack overflow.
As a result of this overflow, excessive data copied onto the stack can overwrite critical parts of the stack frame such as the calling functions' return address.
Since this data is supplied by the user, it could be made to alter the program's flow of execution.
Properly exploited, a maliciously composed AIP file could be used by a remote attacker (either through email or on a remote hostile website) to execute aribitrary code on a vulnerable system.
Winamp is a popular media player supporting MP3 and other filetypes.
Versions of Winamp are vulnerable to a buffer overflow condition triggered during processing of Audiosoft parameter files (*.AIP).
A user may insert a large sequence of characters into an *.AIP file. When parsed by Winamp, the data will cause a stack overflow.
As a result of this overflow, excessive data copied onto the stack can overwrite critical parts of the stack frame such as the calling functions' return address.
Since this data is supplied by the user, it could be made to alter the program's flow of execution.
Properly exploited, a maliciously composed AIP file could be used by a remote attacker (either through email or on a remote hostile website) to execute aribitrary code on a vulnerable system.
Exploit / POC
Solution / Fix
Nullsoft Winamp AIP Buffer Overflow Vulnerability
Solution:
(courtesy ByteRage <[email protected]>):
--
Consider turning off automatic downloading of *.AIP files (also consider turning it off for *.M3U, *.PLS, *.WPZ, *.WSZ), so that if a suspicious webpage or e-mail attempts to open *.AIP files with winamp, you can decide not to hit 'execute from current location'.
--
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
(courtesy ByteRage <[email protected]>):
--
Consider turning off automatic downloading of *.AIP files (also consider turning it off for *.M3U, *.PLS, *.WPZ, *.WSZ), so that if a suspicious webpage or e-mail attempts to open *.AIP files with winamp, you can decide not to hit 'execute from current location'.
--
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nullsoft Winamp AIP Buffer Overflow Vulnerability
References:
References: