CVE-2009-4356 Information

Description

Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (1) JPEG or (2) PNG data in an MP3 file.

Reference

http://forums.winamp.com/showthread.php?threadid=315355 http://www.securityfocus.com/archive/1/508532/100/0/threaded http://www.securityfocus.com/bid/37387 http://www.vupen.com/english/advisories/2009/3576 http://www.vupen.com/exploits/Winamp_png_w5s_PNG_Data_Processing_Integer_Overflow_PoC_3576274.php https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A15743

Share on: