CVE-2002-2392: Medium severity Nullsoft Winamp vulnerability
Published Dec 31, 2002
·Updated
Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.
Affected Software
13 affected components
Nullsoft Winamp=2.72
Nullsoft Winamp=2.73
Nullsoft Winamp=2.75
Nullsoft Winamp=2.65
Nullsoft Winamp=3.1
Nullsoft Winamp=2.76
Nullsoft Winamp=2.80
Nullsoft Winamp=2.74
Nullsoft Winamp=2.71
Nullsoft Winamp=2.78
Nullsoft Winamp=2.77
Nullsoft Winamp=2.70
Nullsoft Winamp=2.79
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Oct 31, 2007
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2392?
CVE-2002-2392 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2002-2392?
To fix CVE-2002-2392, users should upgrade to a later version of Winamp that does not contain this vulnerability.
3
Which versions of Winamp are affected by CVE-2002-2392?
CVE-2002-2392 affects Winamp versions 2.65 through 3.0, including multiple specific versions up to 2.80.
4
What is the impact of CVE-2002-2392?
The impact of CVE-2002-2392 allows remote attackers to execute arbitrary code on the victim's machine.
5
Can CVE-2002-2392 be exploited remotely?
Yes, CVE-2002-2392 can be exploited remotely through specially crafted URL references to malicious skin files.