vendor:
Winamp
by:
Encrypt3d.M!nd
7.5
CVSS
HIGH
Integer Overflow
190
CWE
Product Name: Winamp
Affected Version From: Winamp version 5.0
Affected Version To: Winamp version 5.55
Patch Exists: NO
Related CWE:
CPE: a:nullsoft:winamp:5.55
Platforms Tested: Windows
Winamp <= 5.55 (MAKI script) Universal Integer Overflow Exploit
This exploit targets a universal integer overflow vulnerability in Winamp version 5.55. By placing a specially crafted MAKI script file in the appropriate directory and running Winamp, an attacker can trigger the integer overflow and potentially execute arbitrary code.
Mitigation:
Upgrade to a patched version of Winamp.