CVE-2012-4045: Buffer Overflow
Published Jul 22, 2012
·Updated
Multiple heap-based buffer overflows in bmp.w5s in Winamp before 5.63 build 3235 allow remote attackers to execute arbitrary code via the (1) strf chunk in BIRGB or (2) UYVY video data in an AVI file, or (3) decompressed TechSmith Screen Capture Codec (TSCC) data in an AVI file.
Affected Software
1 affected component
Nullsoft Winamp<=5.63
Event History
Jul 22, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4045?
CVE-2012-4045 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-4045?
To fix CVE-2012-4045, update Winamp to version 5.63 build 3236 or later.
3
What types of files are involved in CVE-2012-4045?
CVE-2012-4045 involves BMP files with strf chunks in BI_RGB format and UYVY video data within AVI files.
4
Can CVE-2012-4045 be exploited remotely?
Yes, CVE-2012-4045 can be exploited remotely, allowing attackers to execute arbitrary code on the affected system.
5
Which versions of Winamp are affected by CVE-2012-4045?
CVE-2012-4045 affects all versions of Winamp prior to 5.63 build 3236.