HIGH
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow
Published May 29, 2009
9.3
HIGHCVSS 2.0
EPSS 36.34%
Description
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.
Affected products
No data.
OR
- ≤ 5.55
- 2.0
- 2.4
- 2.5e
- 2.6x
- 2.7x
- 2.10
- 2.24
- 2.50
- 2.60
- 2.60
- 2.60
- 2.61
- 2.61
- 2.62
- 2.62
- 2.64
- 2.64
- 2.65
- 2.70
- 2.70
- 2.71
- 2.72
- 2.73
- 2.73
- 2.74
- 2.75
- 2.76
- 2.77
- 2.78
- 2.79
- 2.80
- 2.81
- 2.90
- 2.91
- 2.95
- 3.0
- 3.1
- 5.0
- 5.0.1
- 5.0.2
- 5.01
- 5.1
- 5.02
- 5.2
- 5.3
- 5.03
- 5.03a
- 5.04
- 5.05
- 5.5
- 5.06
- 5.07
- 5.08
- 5.08
- 5.08
- 5.08
- 5.08c
- 5.08d
- 5.08e
- 5.09
- 5.11
- 5.12
- 5.13
- 5.21
- 5.22
- 5.23
- 5.24
- 5.31
- 5.32
- 5.33
- 5.34
- 5.35
- 5.36
- 5.51
- 5.52
- 5.53
- 5.54
- 5.091
- 5.093
- 5.094
- 5.111
- 5.112
- 5.541
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://vrt-sourcefire.blogspot.com/2009/05/winamp-maki-parsing-vulnerability.html x_refsource_MISC
- http://www.securityfocus.com/bid/35052 vdb-entryx_refsource_BIDExploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1826 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50664 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15683 vdb-entrysignaturex_refsource_OVAL
- https://www.exploit-db.com/exploits/8767 exploitx_refsource_EXPLOIT-DB
- https://www.exploit-db.com/exploits/8770 exploitx_refsource_EXPLOIT-DB
- https://www.exploit-db.com/exploits/8772 exploitx_refsource_EXPLOIT-DB
- https://www.exploit-db.com/exploits/8783 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://vrt-sourcefire.blogspot.com/2009/05/winamp-maki-parsing-vulnerability.html | x_refsource_MISC | |
| http://www.securityfocus.com/bid/35052 | vdb-entryx_refsource_BIDExploit | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1826 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/50664 | vdb-entryx_refsource_XF | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15683 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.exploit-db.com/exploits/8767 | exploitx_refsource_EXPLOIT-DB | |
| https://www.exploit-db.com/exploits/8770 | exploitx_refsource_EXPLOIT-DB | |
| https://www.exploit-db.com/exploits/8772 | exploitx_refsource_EXPLOIT-DB | |
| https://www.exploit-db.com/exploits/8783 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 29, 2009
Updated Aug 7, 2024
Reserved May 29, 2009
Link CVE-2009-1831
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1826 Assigner mitre
Published May 29, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1826