PC Ekspert Forum

PC Ekspert Forum (https://forum.pcekspert.com/index.php)
-   Softverski problemi (https://forum.pcekspert.com/forumdisplay.php?f=42)
-   -   Winamp "IN_CDDA.dll" Buffer Overflow Vulnerability (https://forum.pcekspert.com/showthread.php?t=14708)

Costa 26.11.2004. 08:51

Winamp "IN_CDDA.dll" Buffer Overflow Vulnerability
 
Software: Winamp 5.x

Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched

Description:
Brett Moore has reported a vulnerability in Winamp, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in the "IN_CDDA.dll" file. This can be exploited in various ways to cause a stack-based buffer overflow e.g. by tricking a user into visiting a malicious web site containing a specially crafted ".m3u" playlist.

Successful exploitation allows execution of arbitrary code.

The vulnerability has been reported in version 5.05 and confirmed in version 5.06. Prior versions may also be affected.

Solution:
Disassociate ".cda" and ".m3u" extensions from Winamp.

http://secunia.com/advisories/13269/


Sva vremena su GMT +2. Sada je 23:57.

Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger