Winamp < 3.0b Multiple File Handling DoS

This script is Copyright (C) 2003-2016 Tenable Network Security, Inc.


Synopsis :

The remote Windows host contains an application affected by multiple
vulnerabilities.

Description :

The remote host is using Winamp3, a popular media player which handles
many files format (mp3, wavs and more...)

This version suffers from multiple buffer overflow and denial of
service issues that can be triggered by specially crafted b4s files.
To perform an attack, the attack would have to send a malformed
playlist (.b4s) to the user of this host who would then have to load
it by double clicking on it.

Note that since .b4s are XML-based files, most antivirus programs will
let them in.

See also :

http://seclists.org/bugtraq/2003/Jan/27
http://forums.winamp.com/showthread.php?postid=823240

Solution :

Upgrade to Winamp 3.0b or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.8
(CVSS2#E:F/RL:U/RC:ND)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 11530 ()

Bugtraq ID: 6515
6516
6517

CVE ID: CVE-2003-1272
CVE-2003-1273
CVE-2003-1274

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now