
Topic: |
Winamp 5.12 - 0day exploit - code execution through playlist |
Credit: |
ATmaCA |
Date: |
2006.01.30 |
CWE: |
N/A |
CVE: |
CVE-2006-0476 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| High |
Yes |
| Yes |
The current version of winamp contains an error in its playlist parsing allowing malicious users to
execute code via a prepared playlist.
This bug can even be triggered through a website - without user interaction - by linking to a pls
file in an IFRAME tag.
Windows DEP (Data Execution Prevention) will stop this bug. If you dont have DEP its strongly
advised to delete Winamp until a non vulnerable version is released.
Greets,
carol
[ ASCII VERSION ]
|