Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
2014-04-16T22:55:06.137
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nullsoft | winamp | ≤ 5.63 | Yes |
Application | nullsoft | winamp | 0.20a | Yes |
Application | nullsoft | winamp | 0.92 | Yes |
Application | nullsoft | winamp | 1.006 | Yes |
Application | nullsoft | winamp | 1.90 | Yes |
Application | nullsoft | winamp | 2.0 | Yes |
Application | nullsoft | winamp | 2.6 | Yes |
Application | nullsoft | winamp | 2.9 | Yes |
Application | nullsoft | winamp | 2.10 | Yes |
Application | nullsoft | winamp | 2.91 | Yes |
Application | nullsoft | winamp | 2.92 | Yes |
Application | nullsoft | winamp | 2.95 | Yes |
Application | nullsoft | winamp | 5.0 | Yes |
Application | nullsoft | winamp | 5.01 | Yes |
Application | nullsoft | winamp | 5.1 | Yes |
Application | nullsoft | winamp | 5.02 | Yes |
Application | nullsoft | winamp | 5.2 | Yes |
Application | nullsoft | winamp | 5.3 | Yes |
Application | nullsoft | winamp | 5.03 | Yes |
Application | nullsoft | winamp | 5.04 | Yes |
Application | nullsoft | winamp | 5.05 | Yes |
Application | nullsoft | winamp | 5.5 | Yes |
Application | nullsoft | winamp | 5.06 | Yes |
Application | nullsoft | winamp | 5.07 | Yes |
Application | nullsoft | winamp | 5.08c | Yes |
Application | nullsoft | winamp | 5.08d | Yes |
Application | nullsoft | winamp | 5.08e | Yes |
Application | nullsoft | winamp | 5.09 | Yes |
Application | nullsoft | winamp | 5.11 | Yes |
Application | nullsoft | winamp | 5.12 | Yes |
Application | nullsoft | winamp | 5.13 | Yes |
Application | nullsoft | winamp | 5.21 | Yes |
Application | nullsoft | winamp | 5.22 | Yes |
Application | nullsoft | winamp | 5.23 | Yes |
Application | nullsoft | winamp | 5.24 | Yes |
Application | nullsoft | winamp | 5.31 | Yes |
Application | nullsoft | winamp | 5.32 | Yes |
Application | nullsoft | winamp | 5.33 | Yes |
Application | nullsoft | winamp | 5.34 | Yes |
Application | nullsoft | winamp | 5.35 | Yes |
Application | nullsoft | winamp | 5.36 | Yes |
Application | nullsoft | winamp | 5.51 | Yes |
Application | nullsoft | winamp | 5.51 | Yes |
Application | nullsoft | winamp | 5.52 | Yes |
Application | nullsoft | winamp | 5.53 | Yes |
Application | nullsoft | winamp | 5.54 | Yes |
Application | nullsoft | winamp | 5.54 | Yes |
Application | nullsoft | winamp | 5.55 | Yes |
Application | nullsoft | winamp | 5.55 | Yes |
Application | nullsoft | winamp | 5.56 | Yes |
Application | nullsoft | winamp | 5.57 | Yes |
Application | nullsoft | winamp | 5.58 | Yes |
Application | nullsoft | winamp | 5.59 | Yes |
Application | nullsoft | winamp | 5.61 | Yes |
Application | nullsoft | winamp | 5.091 | Yes |
Application | nullsoft | winamp | 5.093 | Yes |
Application | nullsoft | winamp | 5.094 | Yes |
Application | nullsoft | winamp | 5.111 | Yes |
Application | nullsoft | winamp | 5.112 | Yes |
Application | nullsoft | winamp | 5.531 | Yes |
Application | nullsoft | winamp | 5.541 | Yes |
Application | nullsoft | winamp | 5.551 | Yes |
Application | nullsoft | winamp | 5.552 | Yes |
Application | nullsoft | winamp | 5.572 | Yes |
Application | nullsoft | winamp | 5.581 | Yes |
Application | nullsoft | winamp | 5.623 | Yes |