PoC Index

CVE-2013-4694

HIGH 7.5EPSS 17.2%

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
17.21% chance of exploitation in the next 30 days, 97th percentile
Published
2014-04-16
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (2)

References

Related