5
CVSSv2

CVE-2002-2195

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Buffer overflow in the version update check for Winamp 2.80 and previous versions allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.

Vulnerable Product Search on Vulmon Subscribe to Product

nullsoft winamp 2.60

nullsoft winamp 2.61

nullsoft winamp 2.62

nullsoft winamp 2.80

nullsoft winamp 2.65

nullsoft winamp 2.70

nullsoft winamp 2.76

nullsoft winamp 2.79

nullsoft winamp 2.71

nullsoft winamp 2.72

nullsoft winamp 2.73

nullsoft winamp 2.74

nullsoft winamp 2.64

nullsoft winamp 2.75

nullsoft winamp 2.78

Exploits

source: wwwsecurityfocuscom/bid/5170/info Nullsoft Winamp is a media player for Microsoft Windows supporting MP3 and other filetypes Winamp is vulnerable to a buffer overflow condition when checking for updated versions A malicious server located at wwwwinampcom may return a malicious response Exploitation may result in the executio ...