Vulnerabilities > CVE-2004-1396 - Unspecified vulnerability in Nullsoft Winamp 5.07
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nullsoft
nessus
Summary
Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | WINAMP_MP4_DOS.NASL |
description | The remote host is using Winamp, a popular media player that handles many file formats (mp3, wavs and more...) The remote version of this software is vulnerable to denial of service attacks when it processes malformed .mp4 / .m4a or .nsv / .nsa files. An attacker may exploit this flaw by sending malformed files to a victim on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15952 |
published | 2004-12-14 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15952 |
title | Winamp < 5.0.7 Multiple File Handling DoS |
code |
|
References
- http://forums.winamp.com/showthread.php?s=&threadid=202007
- http://forums.winamp.com/showthread.php?s=&threadid=202007
- http://marc.info/?l=bugtraq&m=110297310503541&w=2
- http://marc.info/?l=bugtraq&m=110297310503541&w=2
- http://marc.info/?l=full-disclosure&m=110303988101973&w=2
- http://marc.info/?l=full-disclosure&m=110303988101973&w=2
- http://securitytracker.com/alerts/2004/Dec/1012525.html
- http://securitytracker.com/alerts/2004/Dec/1012525.html
- http://www.kb.cert.org/vuls/id/372968
- http://www.kb.cert.org/vuls/id/372968
- http://www.securityfocus.com/bid/11909
- http://www.securityfocus.com/bid/11909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18466
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18466
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18467
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18467