Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
BID:34009
Info
Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
| Bugtraq ID: | 34009 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2009 12:00AM |
| Updated: | Mar 06 2009 07:26PM |
| Credit: | SkD |
| Vulnerable: |
NullSoft Winamp 5.3.2 NullSoft Winamp 5.0 91 NullSoft Winamp 5.0 9 NullSoft Winamp 5.0 8c NullSoft Winamp 5.0 8 NullSoft Winamp 5.0 7 NullSoft Winamp 5.0 6 NullSoft Winamp 5.0 5 NullSoft Winamp 5.0 4 NullSoft Winamp 5.0 3a NullSoft Winamp 5.0 3 NullSoft Winamp 5.0 2 NullSoft Winamp 5.0 1 NullSoft Winamp 3.1 NullSoft Winamp 3.0 NullSoft Winamp 2.91 NullSoft Winamp 2.81 NullSoft Winamp 2.80 NullSoft Winamp 2.79 NullSoft Winamp 2.78 NullSoft Winamp 2.77 NullSoft Winamp 2.76 NullSoft Winamp 2.75 NullSoft Winamp 2.74 NullSoft Winamp 2.73 (full) NullSoft Winamp 2.73 NullSoft Winamp 2.72 NullSoft Winamp 2.71 NullSoft Winamp 2.70 (full) NullSoft Winamp 2.70 NullSoft Winamp 2.65 NullSoft Winamp 2.64 (standard) NullSoft Winamp 2.62 (standard) NullSoft Winamp 2.61 (full) NullSoft Winamp 2.60 (lite) NullSoft Winamp 2.60 (full) NullSoft Winamp 2.50 NullSoft Winamp 2.24 NullSoft Winamp 2.10 NullSoft Winamp 2.6 4 NullSoft Winamp 2.5 E NullSoft Winamp 2.5 e NullSoft Winamp 2.4 NullSoft Winamp 5.541 NullSoft Winamp 5.54 NullSoft Winamp 5.52 NullSoft Winamp 5.51 NullSoft Winamp 5.5 NullSoft Winamp 5.35 NullSoft Winamp 5.34a NullSoft Winamp 5.34 NullSoft Winamp 5.33 NullSoft Winamp 5.31 NullSoft Winamp 5.3 NullSoft Winamp 5.24 NullSoft Winamp 5.22 NullSoft Winamp 5.21 NullSoft Winamp 5.2 NullSoft Winamp 5.13 NullSoft Winamp 5.12 NullSoft Winamp 5.11 NullSoft Winamp 5.094 |
| Not Vulnerable: |
NullSoft Winamp 5.55 |
Discussion
Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
Nullsoft Winamp is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Note that this issue may be related to BID 5832 (Nullsoft Winamp 3 Skin File Buffer Overflow Vulnerability).
Versions prior to Winamp 5.55 are vulnerable.
Nullsoft Winamp is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Note that this issue may be related to BID 5832 (Nullsoft Winamp 3 Skin File Buffer Overflow Vulnerability).
Versions prior to Winamp 5.55 are vulnerable.
Exploit / POC
Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user into loading a malicious skin onto the media player.
The following exploit code is available:
Attackers can exploit this issue by enticing an unsuspecting user into loading a malicious skin onto the media player.
The following exploit code is available:
Solution / Fix
Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
References:
References:
- Winamp Homepage (Nullsoft)