Vulnerability Name:

CVE-2006-0708 (CCN-24739)

Assigned:2006-02-13
Published:2006-02-13
Updated:2018-10-19
Summary:Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
4.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Mon Feb 13 2006 - 14:34:01 CST
New winamp m3u/pls .WMA & .M3U Extension overflows

Source: MITRE
Type: CNA
CVE-2006-0708

Source: MISC
Type: UNKNOWN
http://forums.winamp.com/showthread.php?s=&threadid=238648

Source: SREASON
Type: UNKNOWN
444

Source: SREASON
Type: UNKNOWN
492

Source: CCN
Type: SECTRACK ID: 1015621
Winamp Buffer Overflow in Processing `.m3u` File Names May Let Remote Users Execute Arbitrary Code

Source: SECTRACK
Type: Exploit
1015621

Source: BUGTRAQ
Type: UNKNOWN
20060213 New winamp m3u/pls .WMA & .M3U Extension overflows

Source: CCN
Type: BID-16410
Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability

Source: BID
Type: UNKNOWN
16623

Source: CCN
Type: BID-16623
Nullsoft Winamp M3U File Denial of Service Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-0613

Source: XF
Type: UNKNOWN
winamp-pls-file1-bo(24739)

Source: XF
Type: UNKNOWN
winamp-pls-file1-bo(24739)

Source: XF
Type: UNKNOWN
winamp-m3u-wma-bo(24740)

Source: XF
Type: UNKNOWN
winamp-m3u-filename-bo(24741)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nullsoft:winamp:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.01:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.02:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.03:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.04:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.05:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.06:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.07:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.08c:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.08d:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.08e:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.09:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.11:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.12:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.13:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.091:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.093:*:*:*:*:*:*:*
  • OR cpe:/a:nullsoft:winamp:5.094:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:nullsoft:winamp:5.13:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2006-0708 (CCN-24741)

    Assigned:2006-02-13
    Published:2006-02-13
    Updated:2018-10-19
    Summary:Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.
    CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): High
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): Low
    Availibility (A): Low
    CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
    7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
    4.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Type:CWE-Other
    Vulnerability Consequences:Gain Access
    References:Source: CCN
    Type: BugTraq Mailing List, Mon Feb 13 2006 - 14:34:01 CST
    New winamp m3u/pls .WMA & .M3U Extension overflows

    Source: MITRE
    Type: CNA
    CVE-2006-0708

    Source: CCN
    Type: SECTRACK ID: 1015621
    Winamp Buffer Overflow in Processing `.m3u` File Names May Let Remote Users Execute Arbitrary Code

    Source: CCN
    Type: BID-16410
    Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability

    Source: CCN
    Type: BID-16623
    Nullsoft Winamp M3U File Denial of Service Vulnerability

    Source: XF
    Type: UNKNOWN
    winamp-m3u-filename-bo(24741)

    BACK
    nullsoft winamp 5.0
    nullsoft winamp 5.01
    nullsoft winamp 5.02
    nullsoft winamp 5.03
    nullsoft winamp 5.04
    nullsoft winamp 5.05
    nullsoft winamp 5.06
    nullsoft winamp 5.07
    nullsoft winamp 5.08c
    nullsoft winamp 5.08d
    nullsoft winamp 5.08e
    nullsoft winamp 5.09
    nullsoft winamp 5.11
    nullsoft winamp 5.12
    nullsoft winamp 5.13
    nullsoft winamp 5.091
    nullsoft winamp 5.093
    nullsoft winamp 5.094
    nullsoft winamp 5.13