Heap-based Buffer Overflow in Winamp Plugin Affects Users
CVE-2011-4857

Currently unrated

Key Information:

Vendor

Nullsoft

Status
Vendor
CVE Published:
16 December 2011

What is CVE-2011-4857?

A vulnerability exists in the in_mod.dll plugin for Winamp, prior to version 5.623, which may allow remote attackers to execute arbitrary code by sending specially crafted message data within an Impulse Tracker (IT) file. This exploitation method targets the memory heap, leading to unpredictable behavior and potential system compromise.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.