First published: Mon Dec 17 2007(Updated: )
Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. NOTE: for exploitation, the victim must select a certain menu option at the time of the attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NullSoft Winamp | =5.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6403 is classified as a high severity vulnerability due to the potential for remote code execution.
To mitigate CVE-2007-6403, update to a newer version of Winamp that has addressed this vulnerability.
CVE-2007-6403 affects users of Nullsoft Winamp version 5.32 who open specially crafted .mp4 files.
CVE-2007-6403 allows user-assisted remote attackers to execute arbitrary code by exploiting a stack-based buffer overflow.
Yes, CVE-2007-6403 is related to CVE-2007-2498, which also involves buffer overflow issues in media files.