CVE-2011-3834: Buffer Overflow
Multiple integer overflows in the inavi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a crafted value for (1) the number of streams or (2) the size of the RIFF INFO chunk, leading to a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3834?
CVE-2011-3834 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2011-3834?
To fix CVE-2011-3834, you should upgrade to the latest version of Winamp that is not affected, specifically version 5.623 or later.
What versions of Winamp are affected by CVE-2011-3834?
CVE-2011-3834 affects multiple versions of Winamp, including versions from 0.92 up to 5.622.
Can CVE-2011-3834 be exploited remotely?
Yes, CVE-2011-3834 can be exploited remotely by attackers via specially crafted AVI files.
What components of Winamp are vulnerable in CVE-2011-3834?
The vulnerability in CVE-2011-3834 resides in the in_avi.dll plugin of Winamp.