First published: Wed Jul 05 2017(Updated: )
Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address may be used as a return value starting at f263!GetWinamp5SystemComponent+0x0000000000001951."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NullSoft Winamp | =5.666 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10726 is considered critical due to the potential for arbitrary code execution and denial of service.
Updating to a patched version of Winamp or avoiding the use of vulnerable .flv files can mitigate CVE-2017-10726.
CVE-2017-10726 may allow attackers to execute arbitrary code or cause denial of service via specially crafted .flv files.
CVE-2017-10726 affects Winamp version 5.666 Build 3516 (x86).
A temporary workaround for CVE-2017-10726 includes avoiding the playback of .flv files until a secure version is installed.