Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
BID:44094
Info
Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 44094 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-4371 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2010 12:00AM |
| Updated: | Mar 19 2015 09:40AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
NullSoft Winamp 5.5.8 NullSoft Winamp 5.3.2 NullSoft Winamp 5.581 NullSoft Winamp 5.58 NullSoft Winamp 5.572 NullSoft Winamp 5.571 NullSoft Winamp 5.57 NullSoft Winamp 5.56 NullSoft Winamp 5.552 NullSoft Winamp 5.551 NullSoft Winamp 5.55 NullSoft Winamp 5.541 NullSoft Winamp 5.54 NullSoft Winamp 5.531 NullSoft Winamp 5.53 NullSoft Winamp 5.52 NullSoft Winamp 5.51 NullSoft Winamp 5.5.8.2985 NullSoft Winamp 5.5 NullSoft Winamp 5.35 NullSoft Winamp 5.34a NullSoft Winamp 5.34 NullSoft Winamp 5.33 NullSoft Winamp 5.32 NullSoft Winamp 5.31 NullSoft Winamp 5.3 NullSoft Winamp 5.24 NullSoft Winamp 5.23 NullSoft Winamp 5.22 NullSoft Winamp 5.21 NullSoft Winamp 5.2 NullSoft Winamp 5.13 NullSoft Winamp 5.12 NullSoft Winamp 5.112 NullSoft Winamp 5.111 NullSoft Winamp 5.11 NullSoft Winamp 5.10 NullSoft Winamp 5.094 NullSoft Winamp 5.093 NullSoft Winamp 5.091 NullSoft Winamp 5.09 NullSoft Winamp 5.08 NullSoft Winamp 5.07 NullSoft Winamp 5.06 NullSoft Winamp 5.05 NullSoft Winamp 5.04 NullSoft Winamp 5.03 NullSoft Winamp 5.02 NullSoft Winamp 5.01 |
| Not Vulnerable: | |
Discussion
Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
Winamp is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Winamp 5.581 and prior are vulnerable.
Winamp is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Winamp 5.581 and prior are vulnerable.
Exploit / POC
Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
The following proof-of-concept and exploit code is available:
The following proof-of-concept and exploit code is available:
Solution / Fix
Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
References:
References:
- Multiple Buffer Overflows in Winamp (Luigi Auriemma)
- Winamp Homepage (Nullsoft)