PT-2006-7150 · Nullsoft · Winamp Ipod Plugin

Luigi Auriemma

·

Published

2006-12-14

·

Updated

2017-07-29

·

CVE-2006-6547

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Winamp iPod Plugin (ml ipod) versions 2.00 p19 and earlier
Description The issue is related to a buffer overflow in the readAA function, which can be triggered by a long tag in an audible.com audiobook (aa) file. This can cause a denial of service, resulting in an application crash, or potentially allow the execution of arbitrary code.
Recommendations For versions 2.00 p19 and earlier, consider disabling the readAA function in read aa.cpp to prevent potential exploitation until a fix is available. Restrict access to aa files from untrusted sources to minimize the risk of a denial of service or code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6547

Affected Products

Winamp Ipod Plugin