VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-4373
winamp: The in_mp4 plugin in Winamp before 5.6 allows remot...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4373

Original

The in_mp4 plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via crafted (1) metadata or (2) albumart in an invalid MP4 file.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-12-02
Source Information Category:
Advisory, Alert
Last Updated:
2010-12-03




Affected Product Tags
cpe:/a:nullsoft:winamp:0.20a
cpe:/a:nullsoft:winamp:0.92
cpe:/a:nullsoft:winamp:1.006
cpe:/a:nullsoft:winamp:1.90
cpe:/a:nullsoft:winamp:2.0
cpe:/a:nullsoft:winamp:2.10
cpe:/a:nullsoft:winamp:2.6
cpe:/a:nullsoft:winamp:2.9
cpe:/a:nullsoft:winamp:2.91
cpe:/a:nullsoft:winamp:2.92
cpe:/a:nullsoft:winamp:2.95
cpe:/a:nullsoft:winamp:5.0
cpe:/a:nullsoft:winamp:5.01
cpe:/a:nullsoft:winamp:5.02
cpe:/a:nullsoft:winamp:5.03
cpe:/a:nullsoft:winamp:5.04
cpe:/a:nullsoft:winamp:5.05
cpe:/a:nullsoft:winamp:5.06
cpe:/a:nullsoft:winamp:5.07
cpe:/a:nullsoft:winamp:5.08c
cpe:/a:nullsoft:winamp:5.08d
cpe:/a:nullsoft:winamp:5.08e
cpe:/a:nullsoft:winamp:5.09
cpe:/a:nullsoft:winamp:5.091
cpe:/a:nullsoft:winamp:5.093
cpe:/a:nullsoft:winamp:5.094
cpe:/a:nullsoft:winamp:5.11
cpe:/a:nullsoft:winamp:5.111
cpe:/a:nullsoft:winamp:5.112
cpe:/a:nullsoft:winamp:5.12
cpe:/a:nullsoft:winamp:5.13
cpe:/a:nullsoft:winamp:5.1:-:surround
cpe:/a:nullsoft:winamp:5.2
cpe:/a:nullsoft:winamp:5.21
cpe:/a:nullsoft:winamp:5.22
cpe:/a:nullsoft:winamp:5.23
cpe:/a:nullsoft:winamp:5.24
cpe:/a:nullsoft:winamp:5.3
cpe:/a:nullsoft:winamp:5.31
cpe:/a:nullsoft:winamp:5.32
cpe:/a:nullsoft:winamp:5.33
cpe:/a:nullsoft:winamp:5.34
cpe:/a:nullsoft:winamp:5.35
cpe:/a:nullsoft:winamp:5.5
cpe:/a:nullsoft:winamp:5.51
cpe:/a:nullsoft:winamp:5.52
cpe:/a:nullsoft:winamp:5.53
cpe:/a:nullsoft:winamp:5.531
cpe:/a:nullsoft:winamp:5.54
cpe:/a:nullsoft:winamp:5.541
cpe:/a:nullsoft:winamp:5.55
cpe:/a:nullsoft:winamp:5.551
cpe:/a:nullsoft:winamp:5.552
cpe:/a:nullsoft:winamp:5.56
cpe:/a:nullsoft:winamp:5.572
cpe:/a:nullsoft:winamp:5.58
cpe:/a:nullsoft:winamp:5.581 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
CONFIRM http://forums.winamp.com/showthread.php?threadid=159785




CONFIRM http://forums.winamp.com/showthread.php?t=324322




Vulnerability Type Design Error (NVD-CWE-DesignError)





Copyright © 2010 JPCERT/CC All Rights Reserved.