CVE-2006-0708: Buffer Overflow
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0708?
CVE-2006-0708 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2006-0708?
To fix CVE-2006-0708, update NullSoft Winamp to version 5.14 or later where the vulnerability has been patched.
What versions of NullSoft Winamp are affected by CVE-2006-0708?
CVE-2006-0708 affects NullSoft Winamp versions 5.0 through 5.13.
Can CVE-2006-0708 be exploited remotely?
Yes, CVE-2006-0708 can be exploited remotely by attackers through specially crafted media playlist files.
What are the attack vectors for CVE-2006-0708?
The attack vectors for CVE-2006-0708 include m3u files with long URLs and pls files with long fields.