Re: Buffer overflow in WinAMP 2.x

From: William Yodlowsky (wyodlowsat_private)
Date: Fri May 14 1999 - 12:56:28 PDT

  • Next message: Hugo van der Kooij: "Red Hat Linux 6.0 fixes"

    Tested on WinAMP	v2.091 on Win95A and Win95B;
    		 	v2.21 on Win98;
    			v1.9? and v2.21 on WinNT 4.0WS
    
    It produced GPFs on all except WinNT, where it opened but simply didn't
    play.
    
    --Bill
    <wyodlowskyat_private>
    On Wed, 12 May 1999, Wojtek Kaniewski wrote:
    
    > Introduction
    > ------------
    > WinAMP is a popular Windows sound player with support for many file
    > formats (MP3, wave files, modules). It also supports MP3 streaming
    > (let's call it sh0utcast).
    >
    > Description of the problem
    > --------------------------
    > If we tell WinAMP to open file location (Ctrl+L) which is over 256
    > bytes long, it'll produce nice GPF. The bug also appears when loading
    > playlists (.m3u and .pls)
    >
    > What can we do with this bug?
    > -----------------------------
    > Many sh0utcast radios place .pls files on their websites, which contain
    > URL for radio's sh0utcast server.
    >
    > If we'll make b00m.pls file like this...
    >
    >   [playlist]
    >   NumberOfEntries=1
    >   File1=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA... (about 256 A's)
    >
    > and put such link...
    >
    >   <A HREF="b00m.pls">Techno explosion -- The Coolest MP3 Radio</A>
    >
    > on our website, we can make couple of WinAMPs crash. I suppose, that
    > there's a possibility to put our own code in the filename (see cDc-351
    > for details).
    >
    > Nullsoft (producer of WinAMP) has been noticed about the bug two
    > versions ago.
    >
    > --
    > wojtekkaat_private :: http://wojtekka.stone.pl/ :: ^wojtekka@ircnet
    >
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:46:04 PDT