First published: Wed Apr 16 2014(Updated: )
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NullSoft Winamp | <=5.63 | |
NullSoft Winamp | =0.20a | |
NullSoft Winamp | =0.92 | |
NullSoft Winamp | =1.006 | |
NullSoft Winamp | =1.90 | |
NullSoft Winamp | =2.0 | |
NullSoft Winamp | =2.6 | |
NullSoft Winamp | =2.9 | |
NullSoft Winamp | =2.10 | |
NullSoft Winamp | =2.91 | |
NullSoft Winamp | =2.92 | |
NullSoft Winamp | =2.95 | |
NullSoft Winamp | =5.0 | |
NullSoft Winamp | =5.01 | |
NullSoft Winamp | =5.1 | |
NullSoft Winamp | =5.02 | |
NullSoft Winamp | =5.2 | |
NullSoft Winamp | =5.3 | |
NullSoft Winamp | =5.03 | |
NullSoft Winamp | =5.04 | |
NullSoft Winamp | =5.05 | |
NullSoft Winamp | =5.5 | |
NullSoft Winamp | =5.06 | |
NullSoft Winamp | =5.07 | |
NullSoft Winamp | =5.08c | |
NullSoft Winamp | =5.08d | |
NullSoft Winamp | =5.08e | |
NullSoft Winamp | =5.09 | |
NullSoft Winamp | =5.11 | |
NullSoft Winamp | =5.12 | |
NullSoft Winamp | =5.13 | |
NullSoft Winamp | =5.21 | |
NullSoft Winamp | =5.22 | |
NullSoft Winamp | =5.23 | |
NullSoft Winamp | =5.24 | |
NullSoft Winamp | =5.31 | |
NullSoft Winamp | =5.32 | |
NullSoft Winamp | =5.33 | |
NullSoft Winamp | =5.34 | |
NullSoft Winamp | =5.35 | |
NullSoft Winamp | =5.36 | |
NullSoft Winamp | =5.51 | |
NullSoft Winamp | =5.51-beta | |
NullSoft Winamp | =5.52 | |
NullSoft Winamp | =5.53 | |
NullSoft Winamp | =5.54 | |
NullSoft Winamp | =5.54-beta | |
NullSoft Winamp | =5.55 | |
NullSoft Winamp | =5.55-beta | |
NullSoft Winamp | =5.56 | |
NullSoft Winamp | =5.57 | |
NullSoft Winamp | =5.58 | |
NullSoft Winamp | =5.59-beta | |
NullSoft Winamp | =5.61 | |
NullSoft Winamp | =5.091 | |
NullSoft Winamp | =5.093 | |
NullSoft Winamp | =5.094 | |
NullSoft Winamp | =5.111 | |
NullSoft Winamp | =5.112 | |
NullSoft Winamp | =5.531 | |
NullSoft Winamp | =5.541 | |
NullSoft Winamp | =5.551 | |
NullSoft Winamp | =5.552 | |
NullSoft Winamp | =5.572 | |
NullSoft Winamp | =5.581 | |
NullSoft Winamp | =5.623 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.