CVE-2008-0065

Nullsoft Winamp - Memory Corruption

Title source: rule

Description

Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16611
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/winamp_ultravox.rb

Scores

EPSS 0.7236
EPSS Percentile 98.8%

Details

CWE
CWE-119
Status published
Products (3)
winamp/nullsoft_winamp 5.5
winamp/nullsoft_winamp 5.21
winamp/nullsoft_winamp 5.51
Published Jan 22, 2008
Tracked Since Feb 18, 2026