First published: Wed Feb 15 2006(Updated: )
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =5.093 | |
Winamp iPod Plugin | =5.09 | |
Winamp iPod Plugin | =5.05 | |
Winamp iPod Plugin | =5.02 | |
Winamp iPod Plugin | =5.01 | |
Winamp iPod Plugin | =5.12 | |
Winamp iPod Plugin | =5.094 | |
Winamp iPod Plugin | =5.04 | |
Winamp iPod Plugin | =5.08d | |
Winamp iPod Plugin | =5.11 | |
Winamp iPod Plugin | =5.06 | |
Winamp iPod Plugin | =5.07 | |
Winamp iPod Plugin | =5.13 | |
Winamp iPod Plugin | =5.091 | |
Winamp iPod Plugin | =5.03 | |
Winamp iPod Plugin | =5.0 | |
Winamp iPod Plugin | =5.08e | |
Winamp iPod Plugin | =5.08c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0708 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2006-0708, update NullSoft Winamp to version 5.14 or later where the vulnerability has been patched.
CVE-2006-0708 affects NullSoft Winamp versions 5.0 through 5.13.
Yes, CVE-2006-0708 can be exploited remotely by attackers through specially crafted media playlist files.
The attack vectors for CVE-2006-0708 include m3u files with long URLs and pls files with long fields.