CVE-2004-1119: Buffer Overflow
Published Dec 1, 2004
·Updated
Stack-based buffer overflow in INCDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.
Affected Software
6 affected components
Nullsoft Winamp=5.01
Nullsoft Winamp=5.02
Nullsoft Winamp=5.03
Nullsoft Winamp=5.04
Nullsoft Winamp=5.05
Nullsoft Winamp=5.06
Remediation
Patch Available
Event History
Dec 1, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1119?
CVE-2004-1119 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2004-1119?
To mitigate CVE-2004-1119, users should upgrade to a patched version of Winamp that addresses this buffer overflow issue.
3
What versions of Winamp are affected by CVE-2004-1119?
CVE-2004-1119 affects Winamp versions 5.01 through 5.06, including 5.05.
4
What kind of attack does CVE-2004-1119 enable?
CVE-2004-1119 enables remote attackers to execute arbitrary code via a specially crafted .m3u playlist file.
5
Is user intervention required to exploit CVE-2004-1119?
Yes, exploitation of CVE-2004-1119 typically requires the user to open a malicious playlist file.