If geeks love it, we’re on it

WinAmp Blows Another Security Fuse

WinAmp Blows Another Security Fuse

The bug, a boundary error in the “IN_CDDA.dll” file, is the latest in a string of serious vulnerabilities in WinAmp, including an August flaw in the handling of “skin” files which attackers began to exploit before it had been discovered by researchers.

The new bug, the skin file flaw and an April flaw in in the handling of “.xm” files could all be exploited by luring an affected user to a website containing a specific type of file, which would then be automatically downloaded and executed.

This week’s bug can be exploited in a number of ways, the most dangerous being via an “.m3u” playlist file, according to Moore. “When hosted on a website, these files will be automatically downloaded and opened in winamp without any user interaction,” he wrote in Security-Assessment.com’s advisory. “This is enough to cause the overflow that would allow a malicious playlist to overwrite EIP and execute arbitrary code.”

Nullsoft, part of AOL, has patched the bug in WinAmp version 5.06, available from the company’s website. Danish security firm Secunia, which maintains a vulnerabilities database, said the bug was “highly critical”, its second most serious ranking.

Source: TechWorld

Comments

  1. EMT
    EMT Argh... that sucks. I don't want to update Winamp...
  2. Shivian
    Shivian Wouldn't not associating WinAmp as the default player of m3u files solve that?
  3. EMT
    EMT Yeah, sure sounds like it.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!