CVE-2004-1896: Buffer Overflow
Published Dec 31, 2004
·Updated
Heap-based buffer overflow in inmod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.
Affected Software
5 affected components
Nullsoft Winamp=5.0.2
Nullsoft Winamp=3.1
Nullsoft Winamp=2.91
Nullsoft Winamp=5.0.1
Nullsoft Winamp=3.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1896?
CVE-2004-1896 has been classified as a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2004-1896?
To mitigate CVE-2004-1896, users should upgrade to the latest version of Winamp or apply any available security patches.
3
Which versions of Winamp are affected by CVE-2004-1896?
CVE-2004-1896 affects Winamp versions 2.91, 3.0, 3.1, 5.0.1, and 5.0.2.
4
What type of attack does CVE-2004-1896 enable?
CVE-2004-1896 allows remote attackers to execute arbitrary code on a victim's machine via a specially crafted .xm mod media file.
5
Is there any public exploit for CVE-2004-1896?
Yes, there are known exploits for CVE-2004-1896 that demonstrate its capability to execute arbitrary code.