vendor:
Winamp
by:
SYS 49152
7.5
CVSS
HIGH
Stack Overflow
Stack-based Buffer Overflow
CWE
Product Name: Winamp
Affected Version From: Nullsoft Winamp 5.32
Affected Version To: Nullsoft Winamp 5.32
Patch Exists: No
Related CWE: Unknown
CPE: a:nullsoft:winamp:5.32
Platforms Tested: Windows XP SP2 ENG
Unknown
Nullsoft Winamp MP4 tags Stack Overflow
This is a stack overflow vulnerability in Nullsoft Winamp MP4 tags. It allows remote attackers to execute arbitrary code via a crafted MP4 file, leading to a shell on port 49152. The vulnerability is specific to Nullsoft Winamp version 5.32.
Mitigation:
Update to the latest version of Nullsoft Winamp.