3456Third-party advisory
http://securityreason.com/securityalert/3456 CVE-2007-6403
NullSoft Winamp 5.32 - .MP4 Tags Stack Overflow
Record summary
CVE-2007-6403 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. NOTE: for exploitation, the victim must select a certain menu option at the time of the attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNullSoft Winamp 5.32 - .MP4 Tags Stack OverflowExploitDB exploitby SYS 49152Not analyzed1 file
References
420071208 Nullsoft Winamp MP4 tags Stack Overflowmailing list
http://www.securityfocus.com/archive/1/484776/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6403 oval:org.mitre.oval:def:15562vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15562