PT-2003-2217 · Nullsoft · Winamp
Publicado
2003-12-31
·
Atualizado
2017-07-11
·
CVE-2003-1272
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Winamp version 3.0
Description
The issue concerns multiple buffer overflows that can be triggered by a .b4s file with either a long playlist name or a long path in a file argument to the
Playstring parameter. This can cause a denial of service, leading to a crash, and potentially allow the execution of arbitrary code.Recommendations
For Winamp version 3.0, avoid using .b4s files with long playlist names or long paths in file arguments to the
Playstring parameter until a fix is available. As a temporary workaround, consider restricting the use of .b4s files or limiting the length of playlist names and file paths to prevent potential exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Winamp