Vulnerability Name: | CVE-2005-3188 (CCN-24417) | ||||||||
Assigned: | 2005-12-31 | ||||||||
Published: | 2005-12-31 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Buffer overflow in Nullsoft Winamp 5.094 allows remote attackers to execute arbitrary code via (1) an m3u file containing a long line ending in .wma or (2) a pls file containing a long File1 value ending in .wma, a different vulnerability than CVE-2006-0476. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-3188 Source: SREASON Type: UNKNOWN 397 Source: CCN Type: SECTRACK ID: 1015565 Winamp Error in Processing m3u/pls Files With `.wma` File Extension Lets Remote Users Deny Service Source: SECTRACK Type: Patch 1015565 Source: CCN Type: SECTRACK ID: 1015621 Winamp Buffer Overflow in Processing `.m3u` File Names May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: Vendor Advisory 1015621 Source: IDEFENSE Type: Exploit, Patch, Vendor Advisory 20060201 Winamp m3u/pls .WMA Extension Buffer Overflow Vulnerability Source: OSVDB Type: Patch 22975 Source: CCN Type: OSVDB ID: 22975 Winamp m3u/pls .wma Parsing Overflow Source: CCN Type: OSVDB ID: 30142 Winamp Crafted m3u/pls File .wma Parsing Overflow Source: CCN Type: BID-16410 Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability Source: BID Type: UNKNOWN 16462 Source: CCN Type: BID-16462 Nullsoft Winamp Malformed Playlist File WMA Extention Remote Buffer Overflow Vulnerability Source: CCN Type: Winamp Web page WINAMP Source: XF Type: UNKNOWN winamp-wma-ext-bo(24417) Source: XF Type: UNKNOWN winamp-wma-ext-bo(24417) Source: CCN Type: iDEFENSE Security Advisory 02.01.06 Winamp m3u/pls .WMA Extension Buffer Overflow Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |