Winamp < 5.57 Multiple Vulnerabilities

medium Nessus Network Monitor Plugin ID 5267

Synopsis

The remote host has a media player installed that is vulnerable to multiple attack vectors.

Description

The remote host is running Winamp, a media player for Windows. The version of Winamp installed on the remote host is earlier than 5.57. Such versions are potentially affected by multiple vulnerabilities :

- A boundary error in the Module Decoder Plug-in exists when parsing samples and can be exploited to cause a heap-based buffer overflow via a specially crafted 'Impulse Tracker' file. (CVE-2009-3995)

- An error in the Module Decoder Plug-in when parsing 'Ultratracker' files can be exploited to cause a heap-based buffer overflow. (CVE-2009-3996)

- An integer overflow error exists in the Module Decoder Plug-in when parsing 'Oktalyzer' files and can be exploited to cause a heap-based buffer overflow.

- Multiple integer overflow vulnerabilities in the 'jpeg.w5s' and 'png.w5s' filters when processing malformed 'JPEG' and 'PNG' data.

Solution

Upgrade to Winamp version 5.57 or later.

See Also

http://www.nessus.org/u?0e4f075b

http://secunia.com/secunia_research/2009-53

http://secunia.com/secunia_research/2009-56

http://secunia.com/secunia_research/2009-57

http://www.securityfocus.com/archive/1/508532/30/0/threaded

http://www.winamp.com/help/Version_History#Winamp_5.57

Plugin Details

Severity: Medium

ID: 5267

Family: Generic

Published: 12/17/2009

Updated: 3/6/2019

Nessus ID: 43181

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:nullsoft:winamp

Patch Publication Date: 12/17/2009

Vulnerability Publication Date: 12/17/2009

Exploitable With

Core Impact

Reference Information

CVE: CVE-2009-3995, CVE-2009-3996, CVE-2009-3997, CVE-2009-4356

BID: 37374, 37387