CVE-2002-0546: High severity Nullsoft Winamp vulnerability
Published Jul 3, 2002
·Updated
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.
Affected Software
2 affected components
Nullsoft Winamp=2.78
Nullsoft Winamp=2.79
Event History
Jul 3, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0546?
CVE-2002-0546 has a moderate severity rating due to the potential for unauthorized script execution.
2
How do I fix CVE-2002-0546?
To fix CVE-2002-0546, upgrade to Winamp versions later than 2.79 that do not contain this vulnerability.
3
What software is affected by CVE-2002-0546?
CVE-2002-0546 affects Winamp versions 2.78 and 2.79.
4
What type of vulnerability is CVE-2002-0546?
CVE-2002-0546 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2002-0546 be exploited remotely?
Yes, CVE-2002-0546 can be exploited remotely by embedding malicious scripts in MP3 files.