vendor:
Winamp
by:
Praveen Darshanam
7,5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: Winamp
Affected Version From: Winamp v5.571(x86)
Affected Version To: Winamp v5.571(x86)
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
Unknown
Winamp v5.571 malicious AVI file handling DoS Vulnerability
This vulnerability allows an attacker to cause a denial of service (DoS) by creating a malicious AVI file and opening it in Winamp v5.571(x86). The malicious AVI file is a zero size file which causes a crash when opened in Winamp. The status of this bug can be found at http://forums.winamp.com/showthread.php?s=&threadid=316000. The code works on Python 3.0. To make it work on <3.0 remove braces in print.
Mitigation:
Upgrade to the latest version of Winamp to mitigate this vulnerability.