Vector: | Remote |
Severity: | Medium |
Patch: | Patched |
Impact: |
Denial of Service (DoS) Remote Code Execution (RCE) |
Software: |
WinAMP 2.x WinAMP 3.x |
A remote code execution vulnerability was reported in WinAMP MIDI File.
Buffer overflow vulnerability exists in the MIDI plug-in "IN_MIDI.DLL" when handling MIDI files. An attacker can exploit this vulnerability by constructing a MIDI file with a "Track data size" value of "0xFFFFFFFF" and tricking a user into playing it.
Solution:
For WinAMP 2.x: Update to WinAMP 3 or use another product.
Links:
http://aluigi.altervista.org/adv/winamp-midi-adv.txt