Bug: Winamp 5.12 - 0day exploit - code execution through playlist (WLB-2006010072 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Winamp 5.12 - 0day exploit - code execution through playlist
 Credit: ATmaCA
 Date: 2006.01.30
 CWE: N/A
 CVE: CVE-2006-0476 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
Yes
Yes

The current version of winamp contains an error in its playlist parsing allowing malicious users to
execute code via a prepared playlist.

This bug can even be triggered through a website - without user interaction - by linking to a pls
file in an IFRAME tag.

Windows DEP (Data Execution Prevention) will stop this bug. If you dont have DEP its strongly
advised to delete Winamp until a non vulnerable version is released.

Greets,
carol

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com