PT-2003-1257 · Nullsoft · Winamp

Published

2003-04-02

·

Updated

2008-09-05

·

CVE-2002-1524

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Winamp 3 version 1.0.0.488
Description A buffer overflow issue exists in the XML parser of the wsabi.dll component. This issue can be triggered by a skin file (.wal) containing a long include file tag, allowing remote attackers to execute arbitrary code.
Recommendations For Winamp 3 version 1.0.0.488, consider avoiding the use of skin files (.wal) with long include file tags until a fix is available. As a temporary workaround, restrict the use of the XML parser in wsabi.dll to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1524

Affected Products

Winamp