Flaw affects versions 5.05 and 5.06
Flaw affects versions 5.05 and 5.06
R E L A T E D   C O N T E N T
ADVERTISEMENT

Hackers exploit critical Winamp flaw

Media player vulnerability could allow execution of arbitrary code

Robert Jaques, vnunet.com 26 Nov 2004
ADVERTISEMENT

IT security experts have uncovered a critical vulnerability in the popular Winamp media player, which could be exploited by hackers to compromise a user's system.

Security expert Brett Moore, from Security-Assessment.com, published an advisory detailing the flaw. "The vulnerability is caused due to a boundary error in the 'IN_CDDA.dll' file," it stated.

"This can be exploited in various ways to cause a stack-based buffer overflow, e.g. by tricking a user into visiting a malicious website containing a specially crafted '.m3u' playlist."

Yesterday the threat level of the flaw was raised to 'critical' after the discovery of a hacker exploit which takes advantage of the vulnerability. Successful exploitation allows execution of arbitrary code, said Moore.

The vulnerability has been reported in version 5.05 and confirmed in version 5.06. Prior versions may also be affected, according to Moore, and the flaw has not been fixed in Winamp version 5.06 contrary to vendor statements.

The best workaround for the hundred of thousands of users of the media player is to disassociate '.cda' and '.m3u' extensions from Winamp.

See also:

Increasing automation and sophisticationAnti-Phishing Working Group reports 'disturbing' new trend  24 Nov 2004
Java Virtual Machine flawSecurity experts predict imminent exploit  24 Nov 2004
Tasin.A B and C delete filesNewly intercepted mutants spreading rapidly  23 Nov 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C#, GUI Developer – Fixed Income – Investment Bank. My client is seeking a strong C# ASP.Net developer to join their Fixed Income area and operate within one of the top tier investment banks in ... more >
| Computer People
Technical Project Manager / SDLC West London, £75k - (Software Development, SDLC), RUP Serious opportunity for hands on Technical Project Manager to join a leading blue chip organisation based in an easily accessible area of ... more >
| Computer People
C# Developer - Nottingham 4 Month Contract Market Rates I have an exciting opportunity for a C# ASP.NETDeveloper working for an established client within Computer People. Working from their offices in Nottingham you’ll be providing ... more >
| JAM Recruitment
Job Ref: AS/20356/TAX Package: c£60,000.00 + Bonus + Benefits Location: Middlesex Job type: International Assignment / Global Mobility / Expatriate Tax Manager Position type: Permanent Hours: Full-time Contact name: Andy Shaw Contact Company: JAM Mobility ... more >
More job opportunities