CVE-2004-1150
Winamp 5.0-5.08c - Stack-Based Buffer Overflow via CDA URL Device Name or Track Number
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1150. PoCs published by Yu Yang.
AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in Nullsoft Winamp's IN_CDDA.dll library by crafting a malicious playlist file. The overflow occurs due to improper validation of user-supplied strings, allowing remote code execution when the playlist is processed.
Description
Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.
Exploits (1)
This exploit leverages a buffer overflow vulnerability in Nullsoft Winamp's IN_CDDA.dll library by crafting a malicious playlist file. The overflow occurs due to improper validation of user-supplied strings, allowing remote code execution when the playlist is processed.