CVE-2004-1150: Buffer Overflow
Stack-based buffer overflow in the incdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1150?
CVE-2004-1150 is rated as high severity due to the stack-based buffer overflow that allows attackers to execute arbitrary code.
How do I fix CVE-2004-1150?
To fix CVE-2004-1150, you should update Winamp to a version later than 5.08c which is not affected by this vulnerability.
What versions of Winamp are affected by CVE-2004-1150?
CVE-2004-1150 affects Winamp versions 5.0 through 5.08c, including several earlier versions like 5.01 to 5.08.
Can CVE-2004-1150 be exploited remotely?
Yes, CVE-2004-1150 can be exploited remotely through specially crafted cda:// URLs.
What type of attack does CVE-2004-1150 enable?
CVE-2004-1150 enables attackers to execute arbitrary code on a vulnerable system preferably through crafted media playlists.