vendor:
Winamp
by:
milw0rm.com
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Winamp
Affected Version From: 5.541
Affected Version To: 5.541
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2009
Winamp <= 5.541 multiples Denial of Services (MP3/AIFF)
Winamp versions 5.541 and earlier are vulnerable to multiple denial of service attacks. A specially crafted MP3 file can cause a denial of service when parsed by Winamp, and a specially crafted AIFF file can cause a denial of service when parsed by Winamp due to a heap overflow.
Mitigation:
Upgrade to the latest version of Winamp