Vulnerability record · CVE-2008-0065 · published 22 January 2008
CVE-2008-0065: Winamp in_mp3.dll stack buffer overflow via Ultravox metadata tags
Winamp · Nullsoft Winamp
Winamp 5.21, 5.5, and 5.51 contain multiple stack-based buffer overflows in in_mp3.dll triggered by long artist or name tags in Ultravox streaming metadata, related to stream title construction. A remote attacker can crash the player or execute arbitrary code in the context of the user running Winamp.
Description
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 base score of 10 with network vector, no authentication, and full confidentiality, integrity, and availability impact, tempered by the age of the product and lack of confirmed in-the-wild exploitation.
What it is
Winamp 5.21, 5.5, and 5.51 contain multiple stack-based buffer overflows in in_mp3.dll triggered by long artist or name tags in Ultravox streaming metadata, related to stream title construction. A remote attacker can crash the player or execute arbitrary code in the context of the user running Winamp.
Impact
Successful exploitation allows remote code execution with the privileges of the Winamp process, giving an attacker full control of the affected host. At minimum, a crafted stream can crash the player.
Attack surface
Reached over the network via a malicious or compromised Ultravox stream whose metadata carries an oversized artist or name tag; no authentication is required, but the victim must open or connect to the stream, so some user interaction is implied.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high (0.61275, 99.1st percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Winamp to a version later than 5.51, which is the last affected release named in the record.
- If upgrade is not possible, disable or remove the in_mp3.dll MP3/streaming input plug-in so Ultravox metadata is not parsed.
- Block or restrict outbound and inbound Ultravox streaming traffic at the network perimeter where feasible.
- Warn users not to open untrusted stream URLs or media links from unknown sources.
Detection
- Monitor for Winamp process crashes or abnormal termination correlated with streaming media playback.
- Inspect network traffic for Ultravox streams containing unusually long artist or name metadata fields.
- Hunt for child processes spawned by winamp.exe, which would indicate code execution rather than a simple crash.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0065 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.