Update Protection against AOL Nullsoft Winamp Ultravox Heap Overflow Vulnerability
| Check Point Reference: | CPAI-2006-144 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA22580 | |
| Industry Reference(s): | CVE-2006-5567 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? AOL Winamp versions 2.666 through 5.3 | ||
| Vulnerability Description A heap-based buffer overflow vulnerability was detected in the multimedia player AOL Nullsoft Winamp. A remote attacker can exploit this vulnerability to execute arbitrary code on an affected system. |
||
|
Update/Patch Available Upgrade to AOL Winamp version 5.31: http://www.winamp.com/player/ |
|
|
Vulnerability Details The vulnerability is due to the applications failure to properly handle 'ultravox-max-msg' headers. An attacker could exploit this flaw by convincing a user to open a specially crafted playlist file that contains a malicious ultravox-max-msg header. Successful exploitation may result in execution of arbitrary code once the Winamp player is loaded. |
Protection Overview
The Update enables the Header Rejection protection to detect and block the vulnerability based on pre-defined header names.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on November 30, 2006 includes the following protections:
Novell eDirectory 'evtFilteredMonitorEventsRequest' Vulnerability (CPAI-2006-137)
Microsoft NetWare Client Service Remote Code Execution Vulnerability (MS06-066) - CPAI-2006-138
Microsoft Workstation Service Buffer Overflow Vulnerability (MS06-070) - CPAI-2006-139
Microsoft XML Remote Code Execution Vulnerability (MS06-071) - CPAI-2006-140
Visual Studio WMI Code Execution Vulnerability (CPAI-2006-141)
Microsoft Agent Remote Code Execution Vulnerability (MS06-068) - CPAI-32006-142
Block MSN Messenger Live 8 (CPAI-2006-143)
AOL Nullsoft Winamp Ultravox Heap Overflow Vulnerability (CPAI-2006-144)