PDA

View Full Version : WinAmp Blows Another Security Fuse


KingFish
24 Nov 2004, 5:08pm
The bug, a boundary error in the "IN_CDDA.dll" file, is the latest in a string of serious vulnerabilities in WinAmp, including an August flaw in the handling of "skin" files which attackers began to exploit before it had been discovered by researchers.

The new bug, the skin file flaw and an April flaw in in the handling of ".xm" files could all be exploited by luring an affected user to a website containing a specific type of file, which would then be automatically downloaded and executed.

This week's bug can be exploited in a number of ways, the most dangerous being via an ".m3u" playlist file, according to Moore. "When hosted on a website, these files will be automatically downloaded and opened in winamp without any user interaction," he wrote in Security-Assessment.com's advisory. "This is enough to cause the overflow that would allow a malicious playlist to overwrite EIP and execute arbitrary code."

Nullsoft, part of AOL, has patched the bug in WinAmp version 5.06, available from the company's website. Danish security firm Secunia, which maintains a vulnerabilities database, said the bug was "highly critical", its second most serious ranking.
Source: TechWorld (http://www.techworld.com/security/news/index.cfm?NewsID=2668&Page=1&pagePos=13)

EMT
24 Nov 2004, 6:30pm
Argh... that sucks. I don't want to update Winamp...

Shivian
25 Nov 2004, 1:41am
Wouldn't not associating WinAmp as the default player of m3u files solve that?

EMT
25 Nov 2004, 5:23am
Yeah, sure sounds like it.