Winamp < 3.0b Multiple File Handling DoS

High Nessus Plugin ID 11530


The remote Windows host contains an application affected by multiple vulnerabilities.


The remote host is using Winamp3, a popular media player which handles many files format (mp3, wavs and more...)

This version suffers from multiple buffer overflow and denial of service issues that can be triggered by specially crafted b4s files.
To perform an attack, the attack would have to send a malformed playlist (.b4s) to the user of this host who would then have to load it by double clicking on it.

Note that since .b4s are XML-based files, most antivirus programs will let them in.


Upgrade to Winamp 3.0b or later.

See Also

Plugin Details

Severity: High

ID: 11530

File Name: winamp_buffer_overflow.nasl

Version: $Revision: 1.20 $

Type: local

Agent: windows

Family: Windows

Published: 2003/04/14

Modified: 2016/11/02

Dependencies: 13855

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 8.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:U/RC:ND

Vulnerability Information

CPE: cpe:/a:nullsoft:winamp

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2003/01/04

Reference Information

CVE: CVE-2003-1272, CVE-2003-1273, CVE-2003-1274

BID: 6515, 6516, 6517

OSVDB: 34427, 34428, 34429