Vulnerabilities > CVE-2003-0765 - Remote Security vulnerability in Winamp

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
nullsoft
exploit available

Summary

The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.

Vulnerable Configurations

Part Description Count
Application
Nullsoft
4

Exploit-Db

descriptionNullSoft Winamp 2.81/2.91/3.0/3.1 MIDI Plugin IN_MIDI.DLL Track Data Size Buffer Overflow Vulnerability. CVE-2003-0765. Dos exploit for windows platform
idEDB-ID:23124
last seen2016-02-02
modified2003-09-08
published2003-09-08
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/23124/
titleNullSoft Winamp 2.81/2.91/3.0/3.1 - MIDI Plugin IN_MIDI.DLL Track Data Size Buffer Overflow Vulnerability