Winamp < 5.601 MIDI Timestamp Stack Buffer Overflow
Medium Nessus Network Monitor Plugin ID 5726
SynopsisThe remote host has a media player installed that is vulnerable to a buffer overflow attack.
DescriptionThe remote host is running Winamp, a media player for Windows.
Versions of Winamp earlier than 5.601 are potentially affected by a stack buffer overflow vulnerability due to an error in the 'in_midi.dll' plugin which improperly serializes timestamps in MIDI file. A specially crafted MIDI file can cause the application to overwrite the saved base pointer and allows execution of arbitrary code.
SolutionUpgrade to Winamp 5.601 or later.