[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-0708Date: (C)2006-02-15   (M)2023-12-22


Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1015621
BID-16623
http://www.securityfocus.com/archive/1/424903/100/0/threaded
SREASON-444
SREASON-492
ADV-2006-0613
http://forums.winamp.com/showthread.php?s=&threadid=238648
winamp-m3u-filename-bo(24741)
winamp-m3u-wma-bo(24740)
winamp-pls-file1-bo(24739)

CPE    18
cpe:/a:nullsoft:winamp:5.08d
cpe:/a:nullsoft:winamp:5.08e
cpe:/a:nullsoft:winamp:5.08c
cpe:/a:nullsoft:winamp:5.12
...

© SecPod Technologies