CVE-2008-0065
Nullsoft Winamp 5.21-5.51 - Remote Code Execution via Ultravox Streaming Metadata
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-0065.
PoCs published by Metasploit, including Metasploit module exploits/windows/browser/winamp_ultravox.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Winamp 5.24 by sending an overly long artist tag in Ultravox streaming metadata, leading to arbitrary code execution. The exploit uses a TCP server to deliver the malicious payload via HTTP.
Description
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
Exploits (2)
This Metasploit module exploits a stack buffer overflow in Winamp 5.24 by sending an overly long artist tag in Ultravox streaming metadata, leading to arbitrary code execution. The exploit uses a TCP server to deliver the malicious payload via HTTP.
This Metasploit module exploits a stack buffer overflow in Winamp 5.24 by sending an overly long artist tag in Ultravox streaming metadata, leading to arbitrary code execution. The exploit uses a TCP server to deliver the malicious payload via HTTP.