First published: Fri May 03 2002(Updated: )
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =2.78 | |
Winamp iPod Plugin | =2.77 | |
Winamp | =2.77 | |
Winamp | =2.78 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-0284 is considered moderate due to the potential exposure of sensitive path information.
To fix CVE-2002-0284, upgrade to Winamp version 2.79 or later, where this vulnerability is addressed.
CVE-2002-0284 affects Winamp versions 2.77 and 2.78.
CVE-2002-0284 could allow malicious web servers to obtain the full path of the Temporary Internet Files directory.
Given its age and the discontinuation of Winamp support, CVE-2002-0284 is generally considered a low threat today.