vendor:
Winamp
by:
2c79cbe14ac7d0b8472d3f129fa1df55
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Winamp
Affected Version From: 2.80a and all previous
Affected Version To: 2.80a and all previous
Patch Exists: YES
Related CWE: N/A
CPE: winamp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Nullsoft Winamp Buffer Overflow Vulnerability
Winamp is vulnerable to a buffer overflow condition when checking for updated versions. A malicious server located at www.winamp.com may return a malicious response. Exploitation may result in the execution of arbitrary code as the Winamp process. It may be possible to exploit this vulnerability if an attacker can control the resolution of the www.winamp.com domain, possibly through DNS cache poisoning.
Mitigation:
Disable the option to check for the latest version from www.winamp.com.