CVE-2004-1119

Winamp 5.05 - Stack-based Buffer Overflow via .m3u Playlist File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1119. PoCs published by k-otik.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Winamp 5.x's handling of M3U playlist files. It crafts a malicious M3U file with a long filename entry that overwrites the stack, leading to arbitrary code execution via embedded shellcode.

Description

Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by k-otik · cremotewindows
https://www.exploit-db.com/exploits/654

This exploit targets a buffer overflow vulnerability in Winamp 5.x's handling of M3U playlist files. It crafts a malicious M3U file with a long filename entry that overwrites the stack, leading to arbitrary code execution via embedded shellcode.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp 5.x (specifically tested on 5.02)
No auth needed
Prerequisites: Victim must open the malicious M3U file in Winamp · Specific version of in_cdda.dll and ntdll.dll (XP SP2)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18197
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110123330404482&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110146036300803&w=2
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11730
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13269/
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=110135574326217&w=2
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/986504
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=110126352412395&w=2
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-11/0369.html

Scores

EPSS 0.1726
EPSS Percentile 96.7%

Details

Status published
Products (6)
nullsoft/winamp 5.01
nullsoft/winamp 5.02
nullsoft/winamp 5.03
nullsoft/winamp 5.04
nullsoft/winamp 5.05
nullsoft/winamp 5.06
Published Jan 10, 2005
Tracked Since Feb 18, 2026