Winamp CVE-2013-4694 Multiple Stack Buffer Overflow Vulnerabilities
BID:60883
Info
Winamp CVE-2013-4694 Multiple Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 60883 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-4694 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 01 2013 12:00AM |
| Updated: | Aug 28 2013 04:09PM |
| Credit: | Julien Ahrens |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Winamp CVE-2013-4694 Multiple Stack Buffer Overflow Vulnerabilities
Winamp is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to properly bound-check user-supplied data before copying it to an insufficiently sized memory buffer.
Successful exploits allow attackers to execute arbitrary code with the privileges of the user running the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
Winamp 5.63 is vulnerable; other versions may also be affected.
Winamp is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to properly bound-check user-supplied data before copying it to an insufficiently sized memory buffer.
Successful exploits allow attackers to execute arbitrary code with the privileges of the user running the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
Winamp 5.63 is vulnerable; other versions may also be affected.
Exploit / POC
Winamp CVE-2013-4694 Multiple Stack Buffer Overflow Vulnerabilities
The following proof of concept and exploit code are available:
The following proof of concept and exploit code are available:
Solution / Fix
Winamp CVE-2013-4694 Multiple Stack Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Winamp CVE-2013-4694 Multiple Stack Buffer Overflow Vulnerabilities
References:
References:
- Winamp Homepage (Nullsoft)