Winamp AVI File RIFF Data Remote Denial of Service Vulnerability
BID:40482
Info
Winamp AVI File RIFF Data Remote Denial of Service Vulnerability
| Bugtraq ID: | 40482 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2010 12:00AM |
| Updated: | Jan 04 2010 12:00AM |
| Credit: | Praveen Darshanam |
| Vulnerable: |
NullSoft Winamp 5.3.2 NullSoft Winamp 5.0 91 NullSoft Winamp 5.0 9 NullSoft Winamp 5.0 8c NullSoft Winamp 5.0 8 NullSoft Winamp 5.0 7 NullSoft Winamp 5.0 6 NullSoft Winamp 5.0 5 NullSoft Winamp 5.0 4 NullSoft Winamp 5.0 3a NullSoft Winamp 5.0 3 NullSoft Winamp 5.0 2 NullSoft Winamp 5.0 1 NullSoft Winamp 5.571 NullSoft Winamp 5.57 NullSoft Winamp 5.56 NullSoft Winamp 5.552 NullSoft Winamp 5.55 NullSoft Winamp 5.541 NullSoft Winamp 5.54 NullSoft Winamp 5.52 NullSoft Winamp 5.51 NullSoft Winamp 5.5 NullSoft Winamp 5.35 NullSoft Winamp 5.34a NullSoft Winamp 5.34 NullSoft Winamp 5.33 NullSoft Winamp 5.31 NullSoft Winamp 5.3 NullSoft Winamp 5.24 NullSoft Winamp 5.22 NullSoft Winamp 5.21 NullSoft Winamp 5.2 NullSoft Winamp 5.13 NullSoft Winamp 5.12 NullSoft Winamp 5.11 NullSoft Winamp 5.10 NullSoft Winamp 5.094 NullSoft Winamp 5.08 NullSoft Winamp 5.06 NullSoft Winamp 5.05 |
| Not Vulnerable: |
NullSoft Winamp 5.572 |
Discussion
Winamp AVI File RIFF Data Remote Denial of Service Vulnerability
Winamp is prone to a remote denial-of-service vulnerability.
Attackers may leverage this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Versions prior to Winamp 5.572 are vulnerable.
Winamp is prone to a remote denial-of-service vulnerability.
Attackers may leverage this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Versions prior to Winamp 5.572 are vulnerable.
Exploit / POC
Winamp AVI File RIFF Data Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Winamp AVI File RIFF Data Remote Denial of Service Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Winamp AVI File RIFF Data Remote Denial of Service Vulnerability
References:
References:
- Opening .avi file is crashing Winamp 5.571 (praveen_recker)
- Winamp 5.572 Changelog (NullSoft)
- Winamp Homepage (Nullsoft)
- Winamp v5.571 malicious AVI file handling DoS Vulnerability ([email protected])