Vulnerability Name: | CVE-2002-1524 (CCN-10228) | ||||||||
Assigned: | 2002-09-29 | ||||||||
Published: | 2002-09-29 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Illegal Instruction Labs Advisory 29.9.2002 Winamp 3 (1.0.0.488) XML parser buffer overflow vulnerability Source: BUGTRAQ Type: Exploit, Vendor Advisory 20020929 IIL Advisory: Winamp 3 (1.0.0.488) XML parser buffer overflow vulnerability Source: MITRE Type: CNA CVE-2002-1524 Source: XF Type: Vendor Advisory winamp-xml-parser-bo(10228) Source: CCN Type: OSVDB ID: 12026 Winamp wsabi.dll XML Parser .wal File File Tag Overflow Source: BID Type: Exploit, Vendor Advisory 5832 Source: CCN Type: BID-5832 Nullsoft Winamp 3 Skin File Buffer Overflow Vulnerability Source: CCN Type: Winamp Web site WINAMP.COM Source: XF Type: UNKNOWN winamp-xml-parser-bo(10228) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |