Nullsoft Winamp自动更新检测缓冲区溢出漏洞

漏洞信息详情

Nullsoft Winamp自动更新检测缓冲区溢出漏洞

漏洞简介

Winamp 2.80及其早期版本的版本自动更新存在缓冲区溢出漏洞。假冒www.winamp.com的远程攻击者可以借助超长服务器响应执行任意代码。

漏洞公告

2c79cbe14ac7d0b8472d3f129fa1df has contributed an unofficial patch which is reported to hardcode the Winamp update site to the static IP address 205.188.245.120. The patch is available as an attachment to the referenced BugTraq post.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>
@yahoo.com>

参考网址

来源: BID
名称: 5170
链接:http://www.securityfocus.com/bid/5170

来源: XF
名称: winamp-auto-update-bo(9488)
链接:http://www.iss.net/security_center/static/9488.php

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享