Winamp minibrowser cross-site scripting using malicious MP3 file
| winamp-mp3-browser-xss (8753) |
Description:
Winamp could allow a remote attacker to embed malicious HTML code in the album field of the ID3v2 tag in a MP3 file to launch the minibrowser in Winamp and open a malicious Web page.
Consequences:
Gain Privileges
Remedy:
This issue has been fixed on the server side by Gracenote.
References:
- BugTraq Mailing List, Wed Apr 03 2002 - 05:23:17 CST: Winamp: Mp3 file can control the minibrowser.
- BugTraq Mailing List, Wed Apr 03 2002 - 16:49:07 CST: Re: Winamp: Mp3 file can control the minibrowser.
- BID-4414: Nullsoft Winamp Script Injection Vulnerability
- CVE-2002-0546: Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.
Platforms Affected:
- Nullsoft Winamp 2.78c
- Nullsoft Winamp 2.79
Reported:
Apr 03, 2002
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
