Vulnerability Name: | CVE-2002-0547 (CCN-8946) | ||||||||
Assigned: | 2002-04-26 | ||||||||
Published: | 2002-04-26 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Vendor Advisory 20020426 Mp3 file can execute code in Winamp [Sandblad advisory #5] Source: CCN Type: Sandblad advisory #5 Mp3 file can execute code in Winamp Source: MITRE Type: CNA CVE-2002-0547 Source: XF Type: Patch, Vendor Advisory winamp-mp3-id3v2-bo(8946) Source: CCN Type: OSVDB ID: 12025 Winamp mini-browser ID3v2 Title Field Overflow Source: BID Type: Patch, Vendor Advisory 4609 Source: CCN Type: BID-4609 Nullsoft Winamp Minibrowser ID3v2 Buffer Overflow Vulnerability Source: CCN Type: Winamp Web site WINAMP.COM Source: MISC Type: Vendor Advisory http://www.winamp.com/download/newfeatures.jhtml Source: XF Type: UNKNOWN winamp-mp3-id3v2-bo(8946) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |