CVE-2013-4694
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
- Affected products
- Winamp
- Nullsoft Winamp
- ≤ 5.63, 0.20a, 0.92, 1.006, 1.90, 2.0, 2.6, 2.9, 2.10, 2.91, 2.92, 2.95, 5.0, 5.01, 5.1, 5.02, 5.2, 5.3, 5.03, 5.04, 5.05, 5.5, 5.06, 5.07, 5.08c, 5.08d, 5.08e, 5.09, 5.11, 5.12, 5.13, 5.21, 5.22, 5.23, 5.24, 5.31, 5.32, 5.33, 5.34, 5.35
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 17.2% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2014-04-16
CVE-2013-4694 at NVD
9 known exploits for CVE-2013-4694
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Cross-site Scripting in Astaro Security_Gateway_Software
WinAmp 5.63 - Stack-based Buffer Overflow
WinAmp 5.63 (winamp.ini) - Local Exploit
WinAmp 5.63 Buffer Overflow
Winamp 5.63 - 'winamp.ini' Local Overflow
WinAmp 5.63 - Stack-based Buffer Overflow Vulnerability
Winamp 5.63 - Stack Buffer Overflow
Winamp 5.63 - Stack Buffer Overflow
WinAmp 5.63 Buffer Overflow