Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Winamp < 5.601 MIDI Timestamp Stack Buffer Overflow

Medium

Synopsis

The remote host has a media player installed that is vulnerable to a buffer overflow attack.

Description

The remote host is running Winamp, a media player for Windows.

Versions of Winamp earlier than 5.601 are potentially affected by a stack buffer overflow vulnerability due to an error in the 'in_midi.dll' plugin which improperly serializes timestamps in MIDI file. A specially crafted MIDI file can cause the application to overwrite the saved base pointer and allows execution of arbitrary code.

Solution

Upgrade to Winamp 5.601 or later.