CVE-2006-5567: Buffer Overflow
Published Oct 27, 2006
·Updated
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.
Affected Software
2 affected components
Nullsoft Winamp=5.24
Nullsoft Winamp=5.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 27, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5567?
CVE-2006-5567 has been classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-5567?
To fix CVE-2006-5567, upgrade to Nullsoft WinAmp version 5.31 or later.
3
What types of attacks are possible with CVE-2006-5567?
CVE-2006-5567 can allow attackers to execute arbitrary code via specially crafted headers and tags.
4
What versions of WinAmp are affected by CVE-2006-5567?
Versions 5.24 and 5.3 of Nullsoft WinAmp are affected by CVE-2006-5567.
5
Is user interaction required for the exploit of CVE-2006-5567?
Yes, user-assisted remote attackers need to craft specific input to exploit CVE-2006-5567.