Winamp Buffer Overflow in Parsing Ultravox Lyrics3 Tags Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1017120
|
|
SecurityTracker URL: http://securitytracker.com/id?1017120
|
|
CVE Reference: CVE-2006-5567
(Links to External Site)
|
Updated: Jun 2 2008
|
Original Entry Date: Oct 25 2006
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: iDEFENSE
|
Version(s): prior to 5.31
|
Description: A vulnerability was reported in Winamp. A remote server can cause arbitrary code to be executed on the target user's system.
The software does not properly parse Ultravox Lyrics3 tags. A remote server can supply specially crafted media to a connected target
user to trigger a heap overflow and execute arbitrary code on the target user's system. The code will run with the privileges of
the target user.
A playlist file, a 'shout:' URI, or a 'uvox:' URI are possible attack methods.
The vendor was notified on
October 19, 2006.
iDEFENSE reported this vulnerability.
The original advisory is available at:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?
id=432
|
Impact: A remote server can execute arbitrary code on the connected target user's system.
|
Solution: The vendor has issued a fixed version (5.31), available at:
http://www.winamp.com/
|
Vendor URL: www.winamp.com/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 25 Oct 2006 15:14:44 -0400
Subject: AOL Nullsoft Winamp Ultravox Lyrics3 v2.00 tags Heap Overflow Vulnerability
|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=432
|
|