CVE-2000-0049: Buffer Overflow
Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
NullSoft Winampfrom your environment.Uninstall Winamp if it is not required to eliminate the vulnerable client.
- Configuration
Remove the .pls file association or configure Winamp/operating system to not automatically open .pls playlist files.
Winamp Handle .pls files (file association/auto-open) = disabled - Compensating control
Block or filter .pls playlist files at email gateways, web filters, and network perimeter devices to prevent delivery of malicious .pls files.
- Operational
Do not open .pls files from untrusted or unknown sources; avoid loading remote playlists until a vendor-provided fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0049?
CVE-2000-0049 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2000-0049?
To fix CVE-2000-0049, upgrade to a version of Winamp later than 2.10 that does not have this vulnerability.
What software is affected by CVE-2000-0049?
CVE-2000-0049 affects Winamp versions 2.0 and 2.10.
What type of attack can exploit CVE-2000-0049?
CVE-2000-0049 can be exploited by attackers sending a malicious .pls file that triggers a buffer overflow.
Can CVE-2000-0049 lead to data loss?
Yes, if exploited, CVE-2000-0049 may allow attackers to execute commands that can compromise data integrity and confidentiality.