Winamp .m3u and .pls file name buffer overflow
| winamp-playlist-filename-bo (24361) |
Description:
Winamp is vulnerable to a stack-based buffer overflow, caused by improper bounds checking of file names within a playlist. By creating a malicious .pls or .m3u file containing an overly long file name path, a remote attacker could overflow a buffer and execute arbitrary code on the system, once a victim loads the malicious playlist. An attacker could exploit this vulnerability by hosting the malicious .pls or .m3u file on a Web page.
Platforms Affected:
- Nullsoft, Winamp 5.11
- Nullsoft, Winamp 5.12
Remedy:
Upgrade to the latest version of Winamp (5.13 or later), available from the Winamp Web page. See References.
Consequences:
Gain Access
References:
- iDEFENSE Security Advisory 02.01.06, Winamp m3u Parsing Stack Overflow Vulnerability at http://www.idefense.com/intelligence/vulnerabilities/display.php?id=377.
- US-CERT Technical Cyber Security Alert TA06-032A, Winamp Playlist Buffer Overflow at http://www.us-cert.gov/cas/techalerts/TA06-032A.html.
- Winamp Web page, WINAMP at http://www.winamp.com/.
- Winamp Web page, Version History at http://www.winamp.com/.
- BID-16410: Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
- CVE-2006-0476: Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).
- FrSIRT/ADV-2006-0361: Nullsoft Winamp Playlist Handling Multiple Buffer Overflow Vulnerabilities
- SA18649: Winamp Three Playlist Parsing Buffer Overflow Vulnerabilities
- SECTRACK ID: 1015552: Winamp Buffer Overflow in Processing Playlist Files Lets Remote Users Execute Arbitrary Code
- US-CERT VU#604745: Winamp fails to properly handle playlists with long file parameter
Reported:
Jan 30, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
