7.5
CVSSv2

CVE-2013-4694

Published: 16/04/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in gen_jumpex.dll in Winamp prior to 5.64 Build 3418 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

Vulnerable Product Search on Vulmon Subscribe to Product

nullsoft winamp 1.90

nullsoft winamp 2.0

nullsoft winamp 5.0

nullsoft winamp 5.01

nullsoft winamp 5.08d

nullsoft winamp 5.08e

nullsoft winamp 5.111

nullsoft winamp 5.112

nullsoft winamp 5.24

nullsoft winamp 5.3

nullsoft winamp 5.51

nullsoft winamp 5.55

nullsoft winamp 5.581

nullsoft winamp 5.59

nullsoft winamp 0.20a

nullsoft winamp 2.9

nullsoft winamp 2.91

nullsoft winamp 5.04

nullsoft winamp 5.05

nullsoft winamp 5.093

nullsoft winamp 5.094

nullsoft winamp 5.2

nullsoft winamp 5.21

nullsoft winamp 5.33

nullsoft winamp 5.34

nullsoft winamp 5.35

nullsoft winamp 5.531

nullsoft winamp 5.54

nullsoft winamp 5.56

nullsoft winamp 5.57

nullsoft winamp

nullsoft winamp 0.92

nullsoft winamp 1.006

nullsoft winamp 2.92

nullsoft winamp 2.95

nullsoft winamp 5.06

nullsoft winamp 5.07

nullsoft winamp 5.08c

nullsoft winamp 5.1

nullsoft winamp 5.11

nullsoft winamp 5.22

nullsoft winamp 5.23

nullsoft winamp 5.36

nullsoft winamp 5.5

nullsoft winamp 5.541

nullsoft winamp 5.572

nullsoft winamp 5.58

nullsoft winamp 2.10

nullsoft winamp 2.6

nullsoft winamp 5.02

nullsoft winamp 5.03

nullsoft winamp 5.09

nullsoft winamp 5.091

nullsoft winamp 5.12

nullsoft winamp 5.13

nullsoft winamp 5.31

nullsoft winamp 5.32

nullsoft winamp 5.52

nullsoft winamp 5.53

nullsoft winamp 5.551

nullsoft winamp 5.552

nullsoft winamp 5.61

nullsoft winamp 5.623

Exploits

Inshell Security Advisory wwwinshellnet 1 ADVISORY INFORMATION ----------------------- Product: WinAmp Vendor URL: wwwwinampcom Type: Stack-based Buffer Overflow [CWE-121] Date found: 2013-06-05 Date published: 2013-07-01 CVSSv2 Score: Bug #1: 7,5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) Bug #2: 3,7 (AV:L/AC:H/Au:N/ ...
# Exploit Title: winampevilskinpy # Date: 25 August 2013 # Exploit Author: Ayman Sagy <aymansagy@gmailcom> # Vendor Homepage: wwwwinampcom/ # Version: 563 # Tested on: Windows XP Professional SP3 Version 2002 # CVE : 2013-4694 # # Ayman Sagy <aymansagy@gmailcom> August 2013 # # This is an exploit for Bug #1 described in htt ...