First published: Fri Sep 12 2003(Updated: )
The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =3.1 | |
Winamp iPod Plugin | =2.91 | |
Winamp iPod Plugin | =2.81 | |
Winamp iPod Plugin | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0765 has a high severity rating due to its potential for remote code execution.
To fix CVE-2003-0765, users should upgrade to a version of Winamp that is not affected, such as version 3.1 or later.
CVE-2003-0765 affects Winamp versions 2.81, 2.91, and 3.0.
CVE-2003-0765 allows remote attackers to execute arbitrary code via specially crafted MIDI files.
Yes, CVE-2003-0765 can be exploited remotely through the use of malicious MIDI files.