PDA

View Full Version : Winamp 2.91 Buffer Overflow


Roadblock
09-10-2003, 10:40 PM
Source: Geek Newz (www.geeknewz.com)

"Winamp 2.91 uses a default plugin called IN_MIDI.DLL used to play MIDI files. The versions prior and equal to the 3.01 of this plugin let an attacker to execute code on a victim simply setting the "Track data size" value of a MIDI file to 0xffffffff. An important thing (and also the only limit for the attacker) is that doesn't exist only one method to exploit this vulnerability because the effects change about how the user opens the file and what MIDI device he use: drag'n'drop, normal file opening, midiOut and DirectMusic. Then another note is that the code execution doesn't happen ever in the same moment that the file is opened or played, in fact it can happen after the second exception or when you close Winamp (also these effects depend by the 4 options before).

Nullsoft is allready informed, a patch is not available yet.
Get more and detailed informations about the bug over here (http://aluigi.altervista.org/adv/winamp-midi-adv.txt)"

m3wthr33
09-11-2003, 03:14 AM
Winamp 5.1alpha uses version 3.03.

the_dial_up_boy
09-11-2003, 03:22 AM
its for midi files ...
2.91 remains a good winamp version :)

Hova
09-11-2003, 05:55 AM
That is what he is talking about the_dial_up_boy. WinAmp 2.01 uses 3.01, winamp 5a1 uses 3.03 of the in_midi.dll.

Cassavus
09-13-2003, 07:43 PM
I'm a little confused on the subject. I'm running Winamp 2.92. Is this version affected?

Cassavus
09-13-2003, 07:47 PM
Wait...nm, figured it out. Just lost myself there for a moment. Yes, 2.92 is affected by this, since it contains version 3.01 of the plugin.

Kingdom Hearts ~ Buddy Icons ~ Photo Editing and Image Converter ~ Audio Editor ~ Screensaver Maker Final Fantasy ~ Free Ringtones ~ Car Blueprints Wallpapers ~ Emulators ~ Learn Arabic - FreshersHome.com - Jobs in Bangalore