First published: Fri May 29 2009(Updated: )
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =2.6x | |
Winamp iPod Plugin | =5.093 | |
Winamp iPod Plugin | =2.64 | |
Winamp iPod Plugin | =5.36 | |
Winamp iPod Plugin | =5.24 | |
Winamp iPod Plugin | =2.62 | |
Winamp iPod Plugin | =5.111 | |
Winamp iPod Plugin | =2.24 | |
Winamp iPod Plugin | =5.09 | |
Winamp iPod Plugin | =2.70 | |
Winamp iPod Plugin | =2.50 | |
Winamp iPod Plugin | =5.31 | |
Winamp iPod Plugin | =5.05 | |
Winamp iPod Plugin | =2.72 | |
Winamp iPod Plugin | =5.23 | |
Winamp iPod Plugin | =2.73 | |
Winamp iPod Plugin | =2.90 | |
Winamp iPod Plugin | =2.60 | |
Winamp iPod Plugin | =2.61 | |
Winamp iPod Plugin | =5.112 | |
Winamp iPod Plugin | =2.75 | |
Winamp iPod Plugin | =5.02 | |
Winamp iPod Plugin | =5.01 | |
Winamp iPod Plugin | =5.53 | |
Winamp iPod Plugin | =2.62 | |
Winamp iPod Plugin | =5.33 | |
Winamp iPod Plugin | =2.65 | |
Winamp iPod Plugin | =5.54 | |
Winamp iPod Plugin | =5.5 | |
Winamp iPod Plugin | =5.34 | |
Winamp iPod Plugin | =5.0.2 | |
Winamp iPod Plugin | =3.1 | |
Winamp iPod Plugin | =5.12 | |
Winamp iPod Plugin | =5.08-d | |
Winamp iPod Plugin | =2.76 | |
Winamp iPod Plugin | =2.80 | |
Winamp iPod Plugin | =2.91 | |
Winamp iPod Plugin | =5.21 | |
Winamp iPod Plugin | =5.094 | |
Winamp iPod Plugin | =5.1 | |
Winamp iPod Plugin | =2.74 | |
Winamp iPod Plugin | =5.3 | |
Winamp iPod Plugin | =2.71 | |
Winamp iPod Plugin | =5.08-e | |
Winamp iPod Plugin | =5.04 | |
Winamp iPod Plugin | =5.03a | |
Winamp iPod Plugin | =5.32 | |
Winamp iPod Plugin | =2.78 | |
Winamp iPod Plugin | =2.81 | |
Winamp iPod Plugin | =5.08d | |
Winamp iPod Plugin | =5.08 | |
Winamp iPod Plugin | =5.0.1 | |
Winamp iPod Plugin | =2.77 | |
Winamp iPod Plugin | =5.11 | |
Winamp iPod Plugin | =2.5e | |
Winamp iPod Plugin | =2.4 | |
Winamp iPod Plugin | =5.51 | |
Winamp iPod Plugin | =5.06 | |
Winamp iPod Plugin | =5.541 | |
Winamp iPod Plugin | =2.61 | |
Winamp iPod Plugin | =2.0 | |
Winamp iPod Plugin | =5.07 | |
Winamp iPod Plugin | =5.13 | |
Winamp iPod Plugin | =2.10 | |
Winamp iPod Plugin | =2.60 | |
Winamp iPod Plugin | =5.091 | |
Winamp iPod Plugin | =5.52 | |
Winamp iPod Plugin | =5.2 | |
Winamp iPod Plugin | =3.0 | |
Winamp iPod Plugin | =2.70 | |
Winamp iPod Plugin | =2.95 | |
Winamp iPod Plugin | =5.03 | |
Winamp iPod Plugin | =2.7x | |
Winamp iPod Plugin | =2.79 | |
Winamp iPod Plugin | =2.60 | |
Winamp iPod Plugin | =5.0 | |
Winamp iPod Plugin | =2.64 | |
Winamp iPod Plugin | =5.08e | |
Winamp iPod Plugin | =5.08-c | |
Winamp iPod Plugin | <=5.55 | |
Winamp iPod Plugin | =5.35 | |
Winamp iPod Plugin | =5.22 | |
Winamp iPod Plugin | =2.73 | |
Winamp iPod Plugin | =5.08c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-1831 is rated as critical due to the potential for remote code execution.
To fix CVE-2009-1831, update Nullsoft Winamp to version 5.552 or later.
CVE-2009-1831 affects multiple versions of Winamp before 5.552, including versions 2.6x and up to 5.53.
CVE-2009-1831 enables remote attackers to execute arbitrary code via a crafted MAKI file.
Yes, CVE-2009-1831 can be easily exploited by attackers through specially crafted MAKI files.