// For flags

CVE-2008-0065

Winamp Ultravox Streaming Metadata 'in_mp3.dll' - Remote Buffer Overflow

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.

Múltiples desbordamientos de búfer basado en pila en in_mp3.dll en Winamp 5.21, 5.5, y 5.51 permite a atacantes remotos ejecutar código de su elección a través de etiquetas largas (1) artist o (2) name en Ultravox streaming metadata, relacionado con la construcción de títulos del stream.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-01-03 CVE Reserved
  • 2008-01-22 CVE Published
  • 2010-05-09 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Winamp
Search vendor "Winamp"
Nullsoft Winamp
Search vendor "Winamp" for product "Nullsoft Winamp"
5.5
Search vendor "Winamp" for product "Nullsoft Winamp" and version "5.5"
-
Affected
Winamp
Search vendor "Winamp"
Nullsoft Winamp
Search vendor "Winamp" for product "Nullsoft Winamp"
5.21
Search vendor "Winamp" for product "Nullsoft Winamp" and version "5.21"
-
Affected
Winamp
Search vendor "Winamp"
Nullsoft Winamp
Search vendor "Winamp" for product "Nullsoft Winamp"
5.51
Search vendor "Winamp" for product "Nullsoft Winamp" and version "5.51"
-
Affected