Vulnerabilities > CVE-2006-0720 - Unspecified vulnerability in Nullsoft Winamp 5.12/5.13
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Winamp 5.12 - (.m3u) Stack Based Buffer Overflow. CVE-2006-0720. Local exploit for windows platform |
id | EDB-ID:26245 |
last seen | 2016-02-03 |
modified | 2013-06-17 |
published | 2013-06-17 |
reporter | superkojiman |
source | https://www.exploit-db.com/download/26245/ |
title | Winamp 5.12 - .m3u Stack Based Buffer Overflow |
Nessus
NASL family | Windows |
NASL id | WINAMP_52.NASL |
description | The remote host is using Winamp, a popular media player for Windows. The version of Winamp installed on the remote Windows host reportedly crashes if the user tries to open an M3U file with a long filename. In addition, it reportedly contains a buffer overflow flaw that can be exploited using a specially crafted M3U file to either crash the application or possibly even execute arbitrary code remotely. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20973 |
published | 2006-02-25 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20973 |
title | Winamp < 5.2 Multiple Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/122040/winamp512m3u-overflow.txt |
id | PACKETSTORM:122040 |
last seen | 2016-12-05 |
published | 2013-06-16 |
reporter | superkojiman |
source | https://packetstormsecurity.com/files/122040/Winamp-5.12-Buffer-Overflow.html |
title | Winamp 5.12 Buffer Overflow |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:79888 |
last seen | 2017-11-19 |
modified | 2014-07-01 |
published | 2014-07-01 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-79888 |
title | Winamp 5.12 (.m3u) - Stack Based Buffer Overflow |
References
- http://forums.winamp.com/showthread.php?threadid=238648
- http://forums.winamp.com/showthread.php?threadid=238648
- http://securityreason.com/securityalert/476
- http://securityreason.com/securityalert/476
- http://securitytracker.com/id?1015675
- http://securitytracker.com/id?1015675
- http://www.nsfocus.com/english/homepage/research/0601.htm
- http://www.nsfocus.com/english/homepage/research/0601.htm
- http://www.securityfocus.com/archive/1/425888/100/0/threaded
- http://www.securityfocus.com/archive/1/425888/100/0/threaded
- http://www.securityfocus.com/bid/16785
- http://www.securityfocus.com/bid/16785
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24740
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24740