NullSoft Winamp 2.81 ID3v2 ArtistTag Buffer Overrun Vulnerability
BID:6428
Info
NullSoft Winamp 2.81 ID3v2 ArtistTag Buffer Overrun Vulnerability
| Bugtraq ID: | 6428 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 18 2002 12:00AM |
| Updated: | Dec 18 2002 12:00AM |
| Credit: | Discovered by Tony Bettini. |
| Vulnerable: |
NullSoft Winamp 2.81 |
| Not Vulnerable: | |
Discussion
NullSoft Winamp 2.81 ID3v2 ArtistTag Buffer Overrun Vulnerability
It has been reported that Winamp 2.81 is vulnerable to a buffer overrun condition related to handling of ID3v2 information in MP3 files. This may be exploited through maliciously constructed MP3 files to execute arbitrary code on target hosts.
It has been reported that Winamp 2.81 is vulnerable to a buffer overrun condition related to handling of ID3v2 information in MP3 files. This may be exploited through maliciously constructed MP3 files to execute arbitrary code on target hosts.
Exploit / POC
NullSoft Winamp 2.81 ID3v2 ArtistTag Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NullSoft Winamp 2.81 ID3v2 ArtistTag Buffer Overrun Vulnerability
Solution:
According to the author of the original report, the build of Winamp 2.81 available for download from http://www.nullsoft.com has been patched. This has not been confirmed by Symantec. Reinstalling this version may eliminate the vulnerability. Version 3.0 is not vulnerable and users are advised to upgrade to the most recent version.
Solution:
According to the author of the original report, the build of Winamp 2.81 available for download from http://www.nullsoft.com has been patched. This has not been confirmed by Symantec. Reinstalling this version may eliminate the vulnerability. Version 3.0 is not vulnerable and users are advised to upgrade to the most recent version.
References
NullSoft Winamp 2.81 ID3v2 ArtistTag Buffer Overrun Vulnerability
References:
References:
- Multiple Exploitable Buffer Overflows in Winamp (Foundstone)