PT-2003-1257 · Nullsoft · Winamp
Published
2003-04-02
·
Updated
2008-09-05
·
CVE-2002-1524
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Winamp 3 version 1.0.0.488
Description
A buffer overflow issue exists in the XML parser of the wsabi.dll component. This issue can be triggered by a skin file (.wal) containing a long include file tag, allowing remote attackers to execute arbitrary code.
Recommendations
For Winamp 3 version 1.0.0.488, consider avoiding the use of skin files (.wal) with long include file tags until a fix is available. As a temporary workaround, restrict the use of the XML parser in wsabi.dll to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winamp