PT-2009-3430 · Nullsoft · Gen Msn Plugin+1
Skd
·
Published
2009-03-05
·
Updated
2017-09-29
·
CVE-2009-0833
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Winamp version 5.541 with gen msn plugin 0.31
Description
A boundary error in the gen msn.dll of the gen msn plugin for Winamp can be exploited to cause a buffer overflow when processing overly long Winamp playlist entries. This can be achieved by tricking the user into opening a specially crafted playlist file with a long URL in the File1 field. Successful exploitation may allow execution of arbitrary code.
Recommendations
For Winamp version 5.541 with gen msn plugin 0.31, consider disabling the gen msn plugin until a patch is available to prevent exploitation.
As a temporary workaround, avoid opening unfamiliar or suspicious playlist files to minimize the risk of exploitation.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winamp
Gen Msn Plugin