CVE-2008-0065 – Winamp Ultravox Streaming Metadata 'in_mp3.dll' - Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-2008-0065
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles. Múltiples desbordamientos de búfer basado en pila en in_mp3.dll en Winamp 5.21, 5.5, y 5.51 permite a atacantes remotos ejecutar código de su elección a través de etiquetas largas (1) artist o (2) name en Ultravox streaming metadata, relacionado con la construcción de títulos del stream. • https://www.exploit-db.com/exploits/16611 http://secunia.com/advisories/27865 http://secunia.com/secunia_research/2008-2/advisory http://www.securityfocus.com/bid/27344 http://www.vupen.com/english/advisories/2008/0183 http://www.winamp.com/player/version-history https://exchange.xforce.ibmcloud.com/vulnerabilities/39778 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2007-6403 – NullSoft Winamp 5.32 - .MP4 Tags Stack Overflow
https://notcve.org/view.php?id=CVE-2007-6403
Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. NOTE: for exploitation, the victim must select a certain menu option at the time of the attack. Desbordamiento de buffer basado en pila en Nullsoft Winamp 5.32 permite que atacantes remotos con la intervención del usuario ejecuten código a su elección usando código unicode manipulado dentro de un fichero .mp4, con etiquetas manipuladas, contenido en un archivo .rar determinado, un problema relacionado con el CVE-2007-2498. NOTA: para que el abuso tenga lugar, la víctima debe seleccionar una determinada opción del menú en el momento del ataque. • https://www.exploit-db.com/exploits/4703 http://securityreason.com/securityalert/3456 http://www.securityfocus.com/archive/1/484776/100/0/threaded https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15562 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •