CVE-2007-1922: Input Validation
The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in INMOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1922?
CVE-2007-1922 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2007-1922?
To fix CVE-2007-1922, you should upgrade to a newer version of Winamp that is not affected by this vulnerability.
Who is affected by CVE-2007-1922?
CVE-2007-1922 affects users of Winamp version 5.33 specifically when playing .IT and .S3M files.
What types of files are involved in CVE-2007-1922?
CVE-2007-1922 involves crafted .IT and .S3M files that exploit memory corruption issues.
Can CVE-2007-1922 be exploited remotely?
Yes, CVE-2007-1922 can be exploited remotely by attackers through specially crafted audio files.