Vulnerability Note VU#449092
AOL Nullsoft Winamp Lyrics3 heap buffer overflow
Overview
AOL Nullsoft Winamp contains a heap-based buffer overflow in the code that handles Lyrics3 tags. This vulnerability may allow a remote, unauthenticated attacker execute arbitrary code on a vulnerable system.
Description
Lyrics3 is a system for embedding the lyrics inside an MP3 song file. AOL Nullsoft Winamp fails to properly handle malformed Lyrics3 tags, allowing a heap-based buffer overflow to occur. This vulnerability may be triggered by persuading a user to access a specially crafted playlist file or connect to a malicious server with Winamp. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. |
Solution
Upgrade |
Links to malicious playlist files may be accessed using the Shoutcast (shout:) or Ultravox (uvox:) protocols. Disabling these protocols will reduce the chances of exploitation. This can be accomplished by deleting the following registry keys: HKEY_CLASSES_ROOT\ICY HKEY_CLASSES_ROOT\SC HKEY_CLASSES_ROOT\SHOUT HKEY_CLASSES_ROOT\UVOX Do not open Winamp playlist files (.PLS or .M3U) from untrusted sources. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| America Online, Inc. | Affected | - | 26 Oct 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=432
- http://www.winamp.com/player/version_history.php#5.31
- http://www.winamp.com/player/index.php
- http://secunia.com/advisories/22580/
- http://www.id3.org/lyrics3.html
Credit
This vulnerability was reported by iDEFENSE.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: Unknown
- Date Public: 25 Oct 2006
- Date First Published: 26 Oct 2006
- Date Last Updated: 08 Dec 2006
- Severity Metric: 14.39
- Document Revision: 25
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.