1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Winamp Boundary Error and Image Parsing Vulnerabilities

Report ID: SA200906363
Source: F-Secure
Date of Discovery: 21.12.2009
Criticality: Critical
Affects:
Affects:

  • Winamp 5.541
  • Winamp 5.55

Other earlier versions may also be affected.

Compromise From: From remote
Unknown
Compromise Type: System access

Summary

Multiple vulnerabilities have been reported in the Winamp media player. If exploited, the vulnerabilities may allow a remote attacker to access and gain complete control of the system.

Detailed Description

One set of vulnerabiltiies involves boundary errors in the Module Decoder Plug-in (IN_MOD.DLL), which an attacker can exploit using specially crafted files to generate heap-based overflows.

Separate vulnerabilities in the jpeg.w5s and png.w5s image filters may be exploited by an attacker using malformed JPEG or PNG images in a media file to generate an integer overflow.

Solution

Update to the latest version:

Original Reference

-