OSVDB ID: 9195

Title: Winamp Skin File (.WSZ) Local Zone Arbitrary Code Execution

Info

Disclosure

Aug 25, 2004

Discovery

Unknown

Dates

Exploit

Aug 25, 2004

Solution

Unknown

Description

WinAmp contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a user downloads a specifically crafted WinAmp skin from a malicious website. These skins are downloaded without prompting the user when using Internet Explorer. It is possible that the flaw may allow an attacker to to place and execute arbitrary programs resulting in a loss of confidentiality, integrity, or availability.

Classification

Location: Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Public
Disclosure: OSVDB Verified, Uncoordinated Disclosure, Discovered in the Wild

Solution

Upgrade to version 5.0.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

NullSoft

WinAmp

5.0.4
5.0.3
5.0.2
5.0.1
5.0
3.x

References

Credit

  • K-OTik.COM Security Survey Team - Pressek-otik.com - K-OTik.COM Security Survey Team


Direct URL: http://osvdb.org/9195