Winamp Ultravox Streaming Metadata Multiple Stack Buffer Overflow Vulnerabilities
BID:27344
Info
Winamp Ultravox Streaming Metadata Multiple Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 27344 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0065 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2008 12:00AM |
| Updated: | Nov 26 2009 06:45PM |
| Credit: | Carsten Eiram, Secunia Research is credited with the discovery of these issues. |
| Vulnerable: |
NullSoft Winamp 5.51 NullSoft Winamp 5.5 NullSoft Winamp 5.21 |
| Not Vulnerable: |
NullSoft Winamp 5.52 |
Discussion
Winamp Ultravox Streaming Metadata Multiple Stack Buffer Overflow Vulnerabilities
Winamp is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to properly bound-check user-supplied data before copying it to an insufficiently sized memory buffer.
Successful exploits allow attackers to execute arbitrary code with the privileges of the user running the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
These issues affect Winamp 5.51, 5.5, and 5.21; other versions may also be vulnerable.
Winamp is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to properly bound-check user-supplied data before copying it to an insufficiently sized memory buffer.
Successful exploits allow attackers to execute arbitrary code with the privileges of the user running the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
These issues affect Winamp 5.51, 5.5, and 5.21; other versions may also be vulnerable.
Exploit / POC
Winamp Ultravox Streaming Metadata Multiple Stack Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit Framework exploit module is available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit Framework exploit module is available.
Solution / Fix
Winamp Ultravox Streaming Metadata Multiple Stack Buffer Overflow Vulnerabilities
Solution:
The vendor has released Winamp 5.52 to address these issues. Please see the references for details.
Solution:
The vendor has released Winamp 5.52 to address these issues. Please see the references for details.
References
Winamp Ultravox Streaming Metadata Multiple Stack Buffer Overflow Vulnerabilities
References:
References:
- Winamp Download Page (Winamp)
- Winamp Homepage (Nullsoft)
- Winamp Media Player Version History (Winamp)
- Secunia Research: Winamp Ultravox Streaming Metadata Parsing Buffer Overflows (Secunia)