Bugtraq mailing list archives
Buffer overflow in WinAMP 2.x
From: wojtekka () BYDNET COM PL (Wojtek Kaniewski)
Date: Wed, 12 May 1999 13:02:43 +0200
Introduction ------------ WinAMP is a popular Windows sound player with support for many file formats (MP3, wave files, modules). It also supports MP3 streaming (let's call it sh0utcast). Description of the problem -------------------------- If we tell WinAMP to open file location (Ctrl+L) which is over 256 bytes long, it'll produce nice GPF. The bug also appears when loading playlists (.m3u and .pls) What can we do with this bug? ----------------------------- Many sh0utcast radios place .pls files on their websites, which contain URL for radio's sh0utcast server. If we'll make b00m.pls file like this... [playlist] NumberOfEntries=1 File1=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA... (about 256 A's) and put such link... <A HREF="b00m.pls">Techno explosion -- The Coolest MP3 Radio</A> on our website, we can make couple of WinAMPs crash. I suppose, that there's a possibility to put our own code in the filename (see cDc-351 for details). Nullsoft (producer of WinAMP) has been noticed about the bug two versions ago. -- wojtekka () irc pl:: http://wojtekka.stone.pl/ :: ^wojtekka@ircnet
Current thread:
- Windump for Windows Edward Gibbs (May 11)
- fts, du, find Stas Kisel (May 12)
- Re: fts, du, find Jordan Ritter (May 14)
- At Ease 5.0 Security Hole Tim Conrad (May 13)
- Re: At Ease 5.0 Security Hole Vincent Janelle (May 14)
- ssh-1.2.27 is out. Jonas Eriksson (May 14)
- Re: fts...(improved patch) Stas Kisel (May 14)
- Re: fts, du, find Jordan Ritter (May 14)
- Re: fts, du, find Przemyslaw Frasunek (May 14)
- fts, du, find Stas Kisel (May 12)
- Buffer overflow in WinAMP 2.x Wojtek Kaniewski (May 12)
- Re: Buffer overflow in WinAMP 2.x William Yodlowsky (May 14)
- Re: Buffer overflow in WinAMP 2.x Jello Biafra (May 16)
- Microsoft Security Bulletin (MS99-015) aleph1 () UNDERGROUND ORG (May 17)
- Re: Windump for Windows Brett Glass (May 12)
- Source code IS available (Was: Re: Windump for Windows) Ken Williams (May 14)