Skip to main content

Winamp "libsndfile.dll" CAF Processing Integer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 4 Mar 2009 5364 Views

RISK: Medium Risk

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to compromise a vulnerable system.This issue is caused by an integer overflow error in libsndfile.dll when processing CAF description chunks, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious CAF audio file.


Impact

  • Remote Code Execution

System / Technologies affected

  • Winamp version 5.55 and prior

Solutions

Note: There is no patch available for this vulnerability currently.

Workaround:
Do not open untrusted CAF files in Winamp.


Vulnerability Identifier


Source


Related Link