Computer Security
[EN] securityvulns.ru
no-pyccku



WinAmp player buffer overflow
updated since 30.01.2006
Published:25.02.2006
Source:FSIRT
SecurityVulns ID:5711
Type:client
Level:7/10
Description:Buffer overflow on oversized computer name in UNC path of .pls on .m3u file entry. Buffer overflow on oversized WMA playlist file entry. Vulnerability can be exploited for hidden trojan installation.
Affected:NULLSOFT : Winamp 5.12
 NULLSOFT : Winamp 5.13
Original documentdocumentadvisories_(at)_irmplc.com, IRM 018: Winamp 5.13 m3u Playlist Buffer Overflow (25.02.2006)
 documentNSFOCUS, NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability (24.02.2006)
 documentSowhat ., [Full-disclosure] Winamp .m3u fun again ;) (16.02.2006)
 documentb0f www . b0f . net, New winamp m3u/pls .WMA & .M3U Extension overflows (14.02.2006)
 documentIDEFENSE, iDefense Security Advisory 02.01.06: Winamp m3u Parsing Stack Overflow Vulnerability (02.02.2006)
 documentIDEFENSE, iDefense Security Advisory 02.01.06: Winamp m3u/pls .WMA Extension Buffer Overflow Vulnerability (02.02.2006)
 documentCERT, US-CERT Technical Cyber Security Alert TA06-032A -- Winamp Playlist Buffer Overflow (02.02.2006)
Files:Winamp 5.12 Playlist UNC Path Computer Name Overflow Perl Exploit
 Winamp 5.12 Remote Buffer Overflow Universal Exploit
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server