CVE-2002-0284: Low severity Nullsoft Winamp vulnerability
Published May 3, 2002
·Updated
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
Affected Software
2 affected components
Nullsoft Winamp=2.77
Nullsoft Winamp=2.78
Event History
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0284?
The severity of CVE-2002-0284 is considered moderate due to the potential exposure of sensitive path information.
2
How do I fix CVE-2002-0284?
To fix CVE-2002-0284, upgrade to Winamp version 2.79 or later, where this vulnerability is addressed.
3
What software is affected by CVE-2002-0284?
CVE-2002-0284 affects Winamp versions 2.77 and 2.78.
4
What kind of attack can occur due to CVE-2002-0284?
CVE-2002-0284 could allow malicious web servers to obtain the full path of the Temporary Internet Files directory.
5
Is CVE-2002-0284 still a threat today?
Given its age and the discontinuation of Winamp support, CVE-2002-0284 is generally considered a low threat today.