vendor:
Winamp
by:
superkojiman
7.5
CVSS
HIGH
Stack-based buffer overflow
119
CWE
Product Name: Winamp
Affected Version From: 5.12
Affected Version To: 5.13
Patch Exists: NO
Related CWE: CVE-2006-0720
CPE: a:nullsoft:winamp:5.12
Platforms Tested: Windows XP Professional SP2
2006
Winamp 5.12 .m3u stack based buffer overflow
Allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file.
Mitigation:
Update to a patched version of Winamp.