PT-2006-6282 · Nullsoft · Winamp

Publicado

2006-10-27

·

Atualizado

2017-10-11

·

CVE-2006-5567

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: WinAmp versions prior to 5.31
Description: The issue is related to multiple heap-based buffer overflows that can be triggered by a crafted ultravox-max-msg header to the Ultravox protocol handler or unspecified Lyrics3 tags, allowing user-assisted remote attackers to execute arbitrary code.
Recommendations: For versions prior to 5.31, update to version 5.31 or later to resolve the issue. As a temporary workaround, consider disabling the Ultravox protocol handler until a patch is available. Restrict access to Lyrics3 tags to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5567

Produtos afetados

Winamp