PT-2006-7150 · Nullsoft · Winamp Ipod Plugin
Luigi Auriemma
·
Published
2006-12-14
·
Updated
2017-07-29
·
CVE-2006-6547
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Winamp iPod Plugin (ml ipod) versions 2.00 p19 and earlier
Description
The issue is related to a buffer overflow in the
readAA function, which can be triggered by a long tag in an audible.com audiobook (aa) file. This can cause a denial of service, resulting in an application crash, or potentially allow the execution of arbitrary code.Recommendations
For versions 2.00 p19 and earlier, consider disabling the
readAA function in read aa.cpp to prevent potential exploitation until a fix is available. Restrict access to aa files from untrusted sources to minimize the risk of a denial of service or code execution.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winamp Ipod Plugin