First published: Tue Jul 19 2005(Updated: )
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =5.09 | |
Winamp iPod Plugin | <=5.093 | |
Winamp iPod Plugin | =5.03a | |
Winamp iPod Plugin | =5.091 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2310 affects Winamp versions 5.03a, 5.09, 5.091, and all versions prior to 5.094.
CVE-2005-2310 is a buffer overflow vulnerability that can allow remote attackers to execute arbitrary code.
To mitigate risks for CVE-2005-2310, it is recommended to upgrade to Winamp version 5.094 or later.
Attackers can exploit CVE-2005-2310 by crafting an MP3 file with a long ID3v2 tag to trigger the buffer overflow.
Yes, CVE-2005-2310 can be easily exploited by sending a specially crafted MP3 file to the target user.