PT-2012-5164 · Nullsoft · Winamp
Published
2012-07-22
·
Updated
2017-09-19
·
CVE-2012-4045
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Winamp versions prior to 5.63 build 3235
Description
The issue is related to multiple heap-based buffer overflows in the bmp.w5s component. This can be exploited by remote attackers to execute arbitrary code through various means, including the strf chunk in BI RGB, UYVY video data in an AVI file, or decompressed TechSmith Screen Capture Codec (TSCC) data in an AVI file.
Recommendations
For versions prior to 5.63 build 3235, update to version 5.63 build 3235 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the bmp.w5s component or restricting access to AVI files until the update is applied.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winamp