Vulnerability Name: | CVE-2006-0476 (CCN-24361) | ||||||||
Assigned: | 2006-01-30 | ||||||||
Published: | 2006-01-30 | ||||||||
Updated: | 2018-10-19 | ||||||||
Summary: | Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field). | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0476 Source: CCN Type: SA18649 Winamp Three Playlist Parsing Buffer Overflow Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 18649 Source: SREASON Type: UNKNOWN 386 Source: SREASON Type: UNKNOWN 398 Source: CCN Type: SECTRACK ID: 1015552 Winamp Buffer Overflow in Processing Playlist Files Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1015552 Source: MISC Type: UNKNOWN http://www.heise.de/newsticker/meldung/68981 Source: CCN Type: US-CERT VU#604745 Winamp fails to properly handle playlists with long file parameter Source: CERT-VN Type: US Government Resource VU#604745 Source: OSVDB Type: UNKNOWN 22789 Source: CCN Type: OSVDB ID: 22789 Winamp Playlist Processing File Tag Overflow Source: BUGTRAQ Type: UNKNOWN 20060130 Winamp 5.12 - 0day exploit - code execution through playlist Source: BUGTRAQ Type: UNKNOWN 20060131 Re: Re: Winamp 5.12 - 0day exploit - code execution through playlist Source: BID Type: UNKNOWN 16410 Source: CCN Type: BID-16410 Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-032A Winamp Playlist Buffer Overflow Source: CERT Type: US Government Resource TA06-032A Source: VUPEN Type: UNKNOWN ADV-2006-0361 Source: CCN Type: Winamp Web page WINAMP Source: MISC Type: UNKNOWN http://www.winamp.com/player/version_history.php Source: XF Type: UNKNOWN winamp-playlist-filename-bo(24361) Source: XF Type: UNKNOWN winamp-playlist-filename-bo(24361) Source: CCN Type: iDEFENSE Security Advisory 02.01.06 Winamp m3u Parsing Stack Overflow Vulnerability Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1402 Source: EXPLOIT-DB Type: UNKNOWN 3422 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |