PT-2003-2217 · Nullsoft · Winamp
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1272
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Winamp version 3.0
Description
The issue concerns multiple buffer overflows that can be triggered by a .b4s file with either a long playlist name or a long path in a file argument to the
Playstring parameter. This can cause a denial of service, leading to a crash, and potentially allow the execution of arbitrary code.Recommendations
For Winamp version 3.0, avoid using .b4s files with long playlist names or long paths in file arguments to the
Playstring parameter until a fix is available. As a temporary workaround, consider restricting the use of .b4s files or limiting the length of playlist names and file paths to prevent potential exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winamp