Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NullSoft Winamp Update 代码注入漏洞
Vulnerability Description
Winamp是一款比较流行的媒体播放软件。 Nullsoft Winamp 5.24之前的版本没有正确地校验更新的真实性,导致恶意代码注入漏洞。通过中间人攻击方式,可以利用此漏洞在升级中利用包含木马的更新,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A