CVE-2013-4694

UnknownEPSS 17.21%

Last modified

CVE-2013-4694 is a vulnerability of currently unknown severity. Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. EPSS estimates a 17.21% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

Metrics

EPSS Probability
17.21%

96.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
NullsoftWinamp<= 5.63—
NullsoftWinamp0.20a—
NullsoftWinamp0.92—
NullsoftWinamp1.006—
NullsoftWinamp1.90—
NullsoftWinamp2.0—
NullsoftWinamp2.6—
NullsoftWinamp2.9—
NullsoftWinamp2.10—
NullsoftWinamp2.91—
NullsoftWinamp2.92—
NullsoftWinamp2.95—
NullsoftWinamp5.0—
NullsoftWinamp5.01—
NullsoftWinamp5.1—
NullsoftWinamp5.02—
NullsoftWinamp5.2—
NullsoftWinamp5.3—
NullsoftWinamp5.03—
NullsoftWinamp5.04—
NullsoftWinamp5.05—
NullsoftWinamp5.5—
NullsoftWinamp5.06—
NullsoftWinamp5.07—
NullsoftWinamp5.08c—
NullsoftWinamp5.08d—
NullsoftWinamp5.08e—
NullsoftWinamp5.09—
NullsoftWinamp5.11—
NullsoftWinamp5.12—
NullsoftWinamp5.13—
NullsoftWinamp5.21—
NullsoftWinamp5.22—
NullsoftWinamp5.23—
NullsoftWinamp5.24—
NullsoftWinamp5.31—
NullsoftWinamp5.32—
NullsoftWinamp5.33—
NullsoftWinamp5.34—
NullsoftWinamp5.35—
NullsoftWinamp5.36—
NullsoftWinamp5.51—
NullsoftWinamp5.52—
NullsoftWinamp5.53—
NullsoftWinamp5.54—
NullsoftWinamp5.55—
NullsoftWinamp5.56—
NullsoftWinamp5.57—
NullsoftWinamp5.58—
NullsoftWinamp5.59Beta

Showing 50 of 63 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-4694?
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
How severe is CVE-2013-4694?
Severity scoring for CVE-2013-4694 is pending analysis. The EPSS model estimates a 17.21% probability of exploitation in the next 30 days.
How do I fix CVE-2013-4694?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2013

Are you affected by CVE-2013-4694?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST