N_MIDI.DLL插件3.01漏洞

N_MIDI.DLL插件3.01漏洞

漏洞ID 1107474 漏洞类型 未知
发布时间 2003-09-08 更新时间 2003-09-17
图片[1]-N_MIDI.DLL插件3.01漏洞-安全小百科CVE编号 CVE-2003-0765
图片[2]-N_MIDI.DLL插件3.01漏洞-安全小百科CNNVD-ID CNNVD-200309-018
漏洞平台 Windows CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23124
https://www.securityfocus.com/bid/82739
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200309-018
|漏洞详情
用于Winamp2.91版本中的N_MIDI.DLL插件3.01及其早期版本存在漏洞。远程攻击者借助带超大“Trackdatasize”值的MIDI文件执行任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/8567/info

Winamp MIDI plugin, IN_MIDI.DLL has been reported prone to a buffer overflow issue when handling malicious MIDI files. The issue presents itself when a malicious value is passed as the Track Data Size of a malicious MIDI file header. Although unconfirmed it has been conjectured that an attacker may exploit this condition to execute arbitrary code in the context of the user who is running the affected Winamp player. 

4 bytes MIDI Header "MThd"
4 bytes Header data size 00000006
2 bytes Format 0000
2 bytes Number of tracks 0001
2 bytes Divisions 0001
4 bytes Track Header "MTrk"
4 bytes Track data size ffffffff <--- bug
... "aaaaaaaaaaaaaaaaaaaaa..." <--- fun
|受影响的产品
NullSoft Winamp 2.91

NullSoft Winamp 3.1

NullSoft Winamp 3.0

NullSoft Winamp 2.81

|参考资料

来源:BUGTRAQ
名称:20030908Winamp2.91letscodeexecutionthroughMIDIfiles
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=106305643432112&w;=2

相关推荐: Nokia Electronic Documentation Cross-Site Scripting Vulnerability

Nokia Electronic Documentation Cross-Site Scripting Vulnerability 漏洞ID 1099489 漏洞类型 Input Validation Error 发布时间 2003-09-15 更新时间 20…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享