Skip to main content

Nullsoft Winamp MIDI System Exclusive Message Processing Integer Underflow Vulnerability

Last Update Date: 17 May 2011 10:41 Release Date: 17 May 2011 5794 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by  an integer underflow error when processing System Exclusive (SysEx) MIDI messages, which could be exploited by attackers to cause a heap-based buffer overflow via a specially crafted MIDI file.


Impact

  • Remote Code Execution

System / Technologies affected

  • Nullsoft Winamp 5.x

Solutions

  • There is no patch available for this vulnerability currently.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link