Vulnerabilities > CVE-2004-2384 - Unspecified vulnerability in Nullsoft Winamp 5.02
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nullsoft
nessus
Summary
NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | WINAMP_LOCAL_BUFFER_OVERRUN.NASL |
description | The remote host is using Winamp, a popular media player that handles many files format (mp3, wavs and more...). The remote version of this software is vulnerable to a local buffer overrun when handling a large file name. This buffer overflow may be exploited to execute arbitrary code on the remote host. An attacker may exploit this flaw by sending a file with a long file name to a victim on the remote host. When the user attempts to open this file using Winamp, a buffer overflow condition will occur. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16199 |
published | 2005-01-18 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/16199 |
title | Winamp < 5.03 Filename Handler Local Buffer Overflow |
code |
|
References
- http://www.securityfocus.com/archive/1/357986
- http://www.securityfocus.com/archive/1/357986
- http://www.securityfocus.com/archive/1/358097
- http://www.securityfocus.com/archive/1/358097
- http://www.securityfocus.com/bid/9920
- http://www.securityfocus.com/bid/9920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15541
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15541