Title : AOL Nullsoft Winamp "libmp4v2" MP4 File Handling Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-1594 CVE ID : CVE-2007-2498
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-30
Technical Description
A vulnerability has been identified in AOL Nullsoft Winamp, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a memory corruption error in the "libmp4v2.dll" module when processing a malformed MP4 file, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a specially crafted MP4 file.