First published: Tue Jan 22 2008(Updated: )
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
NullSoft Winamp | =5.51 | |
NullSoft Winamp | =5.5 | |
NullSoft Winamp | =5.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0065 has a high severity level due to its potential for remote code execution.
To fix CVE-2008-0065, upgrade to a version of Winamp that is not affected, ideally later than 5.51.
CVE-2008-0065 affects Winamp versions 5.21, 5.5, and 5.51.
Yes, CVE-2008-0065 can be exploited remotely through specially crafted Ultravox streaming metadata.
CVE-2008-0065 enables remote attackers to execute arbitrary code on the vulnerable system.