---
cve: "CVE-2013-4694"
severity: "LOW"
cvss: 3.1
epss: "17.2%"
vendor: "n/a"
kev: false
exploited: false
published: "2014-04-16 22:55:06"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T08:42:01+02:00"
---

# CVE-2013-4694

> 3.1 LOW · 🧪 PoC

## Beschreibung

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name.  NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

## Exploit-Evidenz

- [EDB-27874 — Winamp 5.63 - 'winamp.ini' Local Overflow](https://www.exploit-db.com/exploits/27874) ✅
- [EDB-26558 — Winamp 5.63 - Stack Buffer Overflow](https://www.exploit-db.com/exploits/26558) ✅

## Referenzen

- <http://seclists.org/fulldisclosure/2013/Jul/4>
- <http://www.exploit-db.com/exploits/26558>
- <http://forums.winamp.com/showthread.php?t=364291>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/85399>
- <http://osvdb.org/94739>
- <http://packetstormsecurity.com/files/122239/WinAmp-5.63-Buffer-Overflow.html>
- <http://osvdb.org/94740>
- <https://www.rcesecurity.com/2013/07/winamp-v5-64-fixes-several-code-execution-vulnerabilities-cve-2013-4694-cve-2013-4695>
- <http://www.securitytracker.com/id/1030107>
- <http://packetstormsecurity.com/files/122978>
- <http://www.securityfocus.com/bid/60883>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-4694) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
