Vulnerability record · CVE-2006-0476 · published 31 January 2006
CVE-2006-0476: Winamp 5.12 playlist file name buffer overflow
Nullsoft · Winamp
Nullsoft Winamp 5.12 contains a buffer overflow triggered by a long file name in the File1 field of a playlist (.pls) file. Opening a crafted playlist can corrupt memory and allow code execution in the context of the user running Winamp.
Description
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the high attack complexity and required user interaction temper the risk.
What it is
Nullsoft Winamp 5.12 contains a buffer overflow triggered by a long file name in the File1 field of a playlist (.pls) file. Opening a crafted playlist can corrupt memory and allow code execution in the context of the user running Winamp.
Impact
An attacker can execute arbitrary code with the privileges of the Winamp user, leading to full compromise of the host under that account. The CVSS 2.0 vector rates confidentiality, integrity, and availability impact as complete.
Attack surface
The flaw is reached remotely by delivering a malicious .pls file that the victim opens in Winamp; no authentication is required, but user interaction (opening the playlist) is needed. The CVSS 2.0 vector is AV:N/AC:H/Au:N, indicating network delivery with high attack complexity.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.74993, 99.482nd percentile) and a public Exploit-DB entry (3422) exists, indicating exploit code is publicly available. No ransomware usage is documented.
What to do
- Upgrade Winamp to a version later than 5.12 that addresses the playlist parsing overflow.
- Apply the vendor patch referenced in the Secunia advisory (SA18649) if upgrading is not immediately possible.
- Block or strip .pls attachments and downloads at email and web gateways where feasible.
- Train users not to open playlist files from untrusted sources.
- Consider application allowlisting or endpoint controls to limit execution of untrusted media files.
Detection
- Monitor for Winamp processes spawning unexpected child processes or making unusual network connections after opening a .pls file.
- Inspect .pls files for abnormally long File1 values or oversized file name fields.
- Use endpoint detection to flag crashes or memory corruption events in winamp.exe.
- Review file transfer and email logs for .pls files arriving from external or untrusted senders.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0476 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0476), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.