CVE-2003-0339

WsMp3 daemon 0.0.10 - Remote Code Execution via Long HTTP Requests

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0339. PoCs published by Xpl017Elz.

AI-analyzed exploit summary This exploit targets a remote heap corruption vulnerability in WsMp3 Server, allowing arbitrary code execution via a crafted packet. It includes a bindshell payload on port 36864 and supports multiple Linux distributions with predefined return addresses.

Description

Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Xpl017Elz · cremotelinux
https://www.exploit-db.com/exploits/33

This exploit targets a remote heap corruption vulnerability in WsMp3 Server, allowing arbitrary code execution via a crafted packet. It includes a bindshell payload on port 36864 and supports multiple Linux distributions with predefined return addresses.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: WsMp3 Server (versions unspecified, likely older Linux builds)
No auth needed
Prerequisites: Network access to target WsMp3 Server on port 8000 · Target must be running a vulnerable version of WsMp3 Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105353178019353&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105361764807746&w=2

Scores

EPSS 0.0817
EPSS Percentile 94.1%

Details

Status published
Products (4)
wsmp3/wsmp3_daemon 0.0.8
wsmp3/wsmp3_daemon 0.0.9
wsmp3/wsmp3_daemon 0.0.10
wsmp3/wsmp3_web_server 0.0.7
Published May 22, 2003
Tracked Since Feb 18, 2026