Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (1) JPEG or (2) PNG data in an MP3 file.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:09
Type | Values Removed | Values Added |
---|---|---|
References | () http://forums.winamp.com/showthread.php?threadid=315355 - Patch | |
References | () http://www.securityfocus.com/archive/1/508532/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/37387 - | |
References | () http://www.vupen.com/english/advisories/2009/3576 - Vendor Advisory | |
References | () http://www.vupen.com/exploits/Winamp_png_w5s_PNG_Data_Processing_Integer_Overflow_PoC_3576274.php - Exploit, Vendor Advisory | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15743 - |
Information
Published : 2009-12-18 19:30
Updated : 2024-11-21 01:09
NVD link : CVE-2009-4356
Mitre link : CVE-2009-4356
CVE.ORG link : CVE-2009-4356
JSON object : View
Products Affected
nullsoft
- winamp
CWE
CWE-189
Numeric Errors