vendor:
Winamp
by:
Unknown
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: Winamp
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:winamp:winamp
Platforms Tested: Windows
Unknown
Stack Overflow in in_cdda.dll
The cdda library only reserves 20 bytes for names when files are "*.cda". By creating a malicious m3u file with a long name, an attacker can overwrite the stack and execute arbitrary code.
Mitigation:
Update the code to properly handle long file names and prevent stack overflows.