PT-2009-3430 · Nullsoft · Gen Msn Plugin+1
Skd
·
Publicado
2009-03-05
·
Atualizado
2017-09-29
·
CVE-2009-0833
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Winamp version 5.541 with gen msn plugin 0.31
Description
A boundary error in the gen msn.dll of the gen msn plugin for Winamp can be exploited to cause a buffer overflow when processing overly long Winamp playlist entries. This can be achieved by tricking the user into opening a specially crafted playlist file with a long URL in the File1 field. Successful exploitation may allow execution of arbitrary code.
Recommendations
For Winamp version 5.541 with gen msn plugin 0.31, consider disabling the gen msn plugin until a patch is available to prevent exploitation.
As a temporary workaround, avoid opening unfamiliar or suspicious playlist files to minimize the risk of exploitation.
Exploit
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Winamp
Gen Msn Plugin