Advisories Blog | G5 Cyber Security

Winamp Impulse Tracker Instrument Parsing Buffer Overflows

Secunia Research has discovered three vulnerabilities in Winamp, which can be exploited by malicious people to compromise a user’s system. The vulnerabilities are caused by boundary errors in the Module Decoder Plug-in (IN_MOD.DLL) when parsing instrument definitions and can be exploited to cause heap-based buffer overflows via a specially crafted Impulse Tracker file. Successful exploitation may allow execution of arbitrary code.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83981/secunia-witip.txt

Source: https://packetstormsecurity.com/files/83981/Winamp-Impulse-Tracker-Instrument-Parsing-Buffer-Overflows.html

Exit mobile version