CVE-2005-2310

Winamp < 5.093 - Buffer Overflow via Long ID3v2 Tag

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2310. PoCs published by Leon Juranic.

AI-analyzed exploit summary The provided text describes a buffer overflow vulnerability in Winamp's ID3v2 functionality, which can be exploited via malicious MP3 files to achieve remote code execution. The writeup references a binary exploit (25989.mp3) but does not include actual exploit code.

Description

Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Leon Juranic · textremotewindows
https://www.exploit-db.com/exploits/25989

The provided text describes a buffer overflow vulnerability in Winamp's ID3v2 functionality, which can be exploited via malicious MP3 files to achieve remote code execution. The writeup references a binary exploit (25989.mp3) but does not include actual exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Winamp versions 5.03a, 5.09, and 5.091
No auth needed
Prerequisites: Victim must open a malicious MP3 file in Winamp
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014483
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/17897
Exploit, Vendor Advisory x_refsource_misc
http://security.lss.hr/index.php?page=details&ID=LSS-2005-07-14
Various Sources x_refsource_confirm
http://www.winamp.com/player/version_history.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14276
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1106
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16077

Scores

EPSS 0.1313
EPSS Percentile 95.9%

Details

CWE
CWE-119
Status published
Products (4)
nullsoft/winamp 5.03a
nullsoft/winamp 5.09
nullsoft/winamp 5.091
nullsoft/winamp < 5.093
Published Jul 19, 2005
Tracked Since Feb 18, 2026