CVE-2011-3834

Winamp < 5.623 - Remote Code Execution via Crafted AVI File

Title source: llm
STIX 2.1

Description

Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a crafted value for (1) the number of streams or (2) the size of the RIFF INFO chunk, leading to a heap-based buffer overflow.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2011-81/
Various Sources x_refsource_confirm
http://forums.winamp.com/showthread.php?t=332010
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14981
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46882

Scores

EPSS 0.0516
EPSS Percentile 91.6%

Details

CWE
CWE-189
Status published
Products (50)
nullsoft/winamp 0.20a
nullsoft/winamp 0.92
nullsoft/winamp 1.006
nullsoft/winamp 1.90
nullsoft/winamp 2.0
nullsoft/winamp 2.6
nullsoft/winamp 2.9
nullsoft/winamp 2.10
nullsoft/winamp 2.91
nullsoft/winamp 2.92
... and 40 more
Published Dec 16, 2011
Tracked Since Feb 18, 2026