Vulnerabilities > CVE-2003-1272 - Unspecified vulnerability in Nullsoft Winamp 3.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nullsoft
nessus
Summary
Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | WINAMP_BUFFER_OVERFLOW.NASL |
description | The remote host is using Winamp3, a popular media player which handles many files format (mp3, wavs and more...) This version suffers from multiple buffer overflow and denial of service issues that can be triggered by specially crafted b4s files. To perform an attack, the attack would have to send a malformed playlist (.b4s) to the user of this host who would then have to load it by double clicking on it. Note that since .b4s are XML-based files, most antivirus programs will let them in. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11530 |
published | 2003-04-14 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11530 |
title | Winamp < 3.0b Multiple File Handling DoS |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html
- http://www.iss.net/security_center/static/10980.php
- http://www.iss.net/security_center/static/10980.php
- http://www.securityfocus.com/bid/6515
- http://www.securityfocus.com/bid/6515
- http://www.securityfocus.com/bid/6516
- http://www.securityfocus.com/bid/6516
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10981
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10981