VID |
50061 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of WinAMP program which is older than 5.64 has been installed on the host. AOL Nullsoft Winamp is a freely available media player for Microsoft Windows platforms. The installed version of WinAMP is affected by multiple vulnerabilities.
- A buffer overflow exists in the 'ml_local.dll' when passed GUI search fields.
- A buffer overflow exists in the 'gen_jumpex.dll' when handling Skins directory names.
- Invalid pointer dereference vulnerabilities exist in the 'gen_ff.dll' library when loading the links.xml.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://forums.winamp.com/showthread.php?t=364291 http://www.winamp.com/help/Version_History
* Platforms Affected: AOL Nullsoft Winamp versions prior to 5.64 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of winamp (5.64 or later), available from the Nullsoft Winamp Download Web page at http://www.winamp.com/player/ |
Related URL |
CVE-2013-4694,CVE-2013-4695 (CVE) |
Related URL |
60883,60886 (SecurityFocus) |
Related URL |
(ISS) |
|