Advertisement






AOL Nullsoft Winamp LIBSNDFILE.DLL Remote Memory Corruption (Off By Zero)

CVE Category Price Severity
CVE-2006-2453 CWE-119 Not specified High
Author Risk Exploitation Type Date
Colin R. James High Remote 2007-04-13
CPE
cpe:cpe:/a:nullsoft:winamp
CVSS EPSS EPSSP
CVSS:2.6/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2007040049

Below is a copy:

AOL Nullsoft Winamp LIBSNDFILE.DLL Remote Memory Corruption (Off By Zero)
by Piotr Bania <bania.piotr (at) gmail (dot) com [email concealed]>
http://www.piotrbania.com

Severity: Critical - Possible remote code execution.

Software affected: Tested on AOL Nullsoft Winamp v5.33 (x86) Feb 13  
2007 (on Windows XP SP1/SP2).

There exist a large possiblity that any other
software that is using the LIBSNDFILE.DLL component should be 
considered as vulnerable.

Orginal url: 
http://www.piotrbania.com/all/adv/nullsoft-winamp-libsndfile-adv.txt

best regards,
pb

-- 
--------------------------------------------------------------------
Piotr Bania - <bania.piotr (at) gmail (dot) com [email concealed]> - 0xCD, 0x19
Fingerprint: 413E 51C7 912E 3D4E A62A  BFA4 1FF6 689F BE43 AC33
http://www.piotrbania.com  - Key ID: 0xBE43AC33
--------------------------------------------------------------------

- "The more I learn about men, the more I love dogs."

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum