CVE-2004-1150

Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nullsoft:winamp:5.0:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.01:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.02:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.03:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.04:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.05:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.06:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.07:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.08c:*:*:*:*:*:*:*

History

20 Nov 2024, 23:50

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=110684140108614&w=2 - () http://marc.info/?l=bugtraq&m=110684140108614&w=2 -
References () http://secunia.com/advisories/13781 - () http://secunia.com/advisories/13781 -
References () http://www.nsfocus.com/english/homepage/research/0501.htm - Exploit () http://www.nsfocus.com/english/homepage/research/0501.htm - Exploit
References () http://www.securityfocus.com/bid/12381 - () http://www.securityfocus.com/bid/12381 -
References () http://www.winamp.com/player/version_history.php - () http://www.winamp.com/player/version_history.php -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18840 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18840 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:50


NVD link : CVE-2004-1150

Mitre link : CVE-2004-1150

CVE.ORG link : CVE-2004-1150


JSON object : View

Products Affected

nullsoft

  • winamp