CVE-2003-1274: Medium severity nullsoft winamp vulnerability
Published Dec 31, 2003
·Updated
Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux.
Affected Software
1 affected component
Nullsoft Winamp=3.0
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1274?
CVE-2003-1274 is classified as a denial of service vulnerability that can crash Winamp 3.0.
2
How do I fix CVE-2003-1274?
To mitigate CVE-2003-1274, avoid using .b4s files that include MS-DOS device names in the Playstring parameter.
3
Who is affected by CVE-2003-1274?
CVE-2003-1274 affects users of Winamp version 3.0.
4
What kind of attack does CVE-2003-1274 facilitate?
CVE-2003-1274 allows remote attackers to perform a denial of service attack.
5
What format is exploited in CVE-2003-1274?
CVE-2003-1274 is exploited through the use of a .b4s file containing a file: argument with MS-DOS device names.