Computer Security
[EN] securityvulns.ru no-pyccku


Nullsoft WinAmp multiple security vulnerabilities
Published:17.12.2009
Source:
SecurityVulns ID:10480
Type:client
Threat Level:
7/10
Description:Buffer overflows and integer overflows on Oktalyzer, Ultratracker, Impulse Tracker files parsing, JPEG, PNG.
Affected:NULLSOFT : Winamp 5.56
CVE:CVE-2009-3997 (Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary code via an Oktalyzer file that triggers a heap-based buffer overflow.)
 CVE-2009-3996 (Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.)
 CVE-2009-3995 (Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file. NOTE: some of these details are obtained from third party information.)
Original documentdocumentVUPEN Security Research, VUPEN Security Research - Winamp PNG and JPEG Data Integer Overflow Vulnerabilities (17.12.2009)
 documentSECUNIA, Secunia Research: Winamp Oktalyzer Parsing Integer Overflow Vulnerability (17.12.2009)
 documentSECUNIA, Secunia Research: Winamp Ultratracker File Parsing Buffer Overflow (17.12.2009)
 documentSECUNIA, Secunia Research: Winamp Impulse Tracker Sample Parsing Buffer Overflow (17.12.2009)
 documentSECUNIA, Secunia Research: Winamp Impulse Tracker Instrument Parsing Buffer Overflows (17.12.2009)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod