Thu, Feb 16 2006 5:18 Don

Nullsoft Winamp Playlist Handling Multiple Buffer Overflow Vulnerabilities

Advisory ID : FrSIRT/ADV-2006-0613
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-02-15

Technical Description

Multiple vulnerabilities have been identified in Winamp, which could be exploited by remote attackers to take complete control of the affected system.

The first flaw is due to a buffer overflow error when processing a specially crafted playlist containing an overly long media filename, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted playlist.

The second issue is due to a buffer overflow error when processing a playlist (.m3u) with an overly long filename, which could be exploited by remote attackers to execute arbitrary commands and take complete control of an affected system via a specially crafted web page.

Affected Products

Nullsoft Winamp version 5.13 and prior

Solution

The FrSIRT is not aware of any official supplied patch for this issue.

References

http://www.frsirt.com/english/advisories/2006/0613
http://www.frsirt.com/english/reference/5829
Filed under: