Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-04-16 22:55
Updated : 2024-02-04 18:35
NVD link : CVE-2013-4694
Mitre link : CVE-2013-4694
CVE.ORG link : CVE-2013-4694
JSON object : View
Products Affected
nullsoft
- winamp
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer