CVE-2008-0065: Buffer Overflow
Published Jan 22, 2008
·Updated
Multiple stack-based buffer overflows in inmp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
Affected Software
3 affected components
Winamp Nullsoft Winamp=5.51
Winamp Nullsoft Winamp=5.5
Winamp Nullsoft Winamp=5.21
Event History
Jan 22, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0065?
CVE-2008-0065 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2008-0065?
To fix CVE-2008-0065, upgrade to a version of Winamp that is not affected, ideally later than 5.51.
3
What software versions are affected by CVE-2008-0065?
CVE-2008-0065 affects Winamp versions 5.21, 5.5, and 5.51.
4
Can CVE-2008-0065 be exploited remotely?
Yes, CVE-2008-0065 can be exploited remotely through specially crafted Ultravox streaming metadata.
5
What kind of attacks does CVE-2008-0065 enable?
CVE-2008-0065 enables remote attackers to execute arbitrary code on the vulnerable system.