CVE-2008-0065
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 61.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 61.27% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- winamp/nullsoft winamp
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/27865Vendor Advisory
- http://secunia.com/secunia_research/2008-2/advisory/
- http://www.securityfocus.com/bid/27344
- http://www.vupen.com/english/advisories/2008/0183
- http://www.winamp.com/player/version-history
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39778
- http://secunia.com/advisories/27865Vendor Advisory
- http://secunia.com/secunia_research/2008-2/advisory/
- http://www.securityfocus.com/bid/27344
- http://www.vupen.com/english/advisories/2008/0183
- http://www.winamp.com/player/version-history
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39778
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.