vendor:
Winamp
by:
Mighty-D
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: Winamp
Affected Version From: 5.5.8.2985
Affected Version To: 5.5.8.2985
Patch Exists: NO
Related CWE: Unknown
CPE: a:winamp:winamp:5.5.8.2985
Platforms Tested: Windows XP SP3
Unknown
Winamp 5.5.8.2985 (in_mod plugin) Stack Overflow
This exploit is for Winamp version 5.5.8.2985 with the in_mod plugin. It exploits a stack overflow vulnerability in the software. The exploit allows an attacker to execute arbitrary code on a Windows XP SP3 system that is fully patched but does not have ASLR or DEP bypass. The bug was found by a user on the website exploit-db.com and the proof of concept (POC) was created by fdisk. The exploit itself was developed by Mighty-D. The exploit is able to bypass certain security measures and gain control of the system.
Mitigation:
To mitigate this vulnerability, users should update to a newer version of Winamp that is not affected by this exploit. Additionally, enabling ASLR and DEP on the system can help prevent similar vulnerabilities from being exploited.