Results 1 to 7 of 7

Thread: WARNING: Extremely Critical Winamp vulnerability discovered

  1. #1
    Banned
    Join Date
    Jan 2004
    Posts
    718

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    props to The Register for this report:
    [blockquote]
    Security researchers are warning of a serious - and unfixed - security hole with the popular Winamp media player.

    A remotely exploitable stack based buffer overflow creates a means for hackers to take over machines running Winamp- providing they can trick users into running maliciously constructed files. For example, a malformed .m3u playlist file, hosted on a web site, would be automatically downloaded and opened in Winamp without any user interaction. The vulnerability, discovered by pen testers at Security-Assessment.com, arises from a buffer overflow in library file (called IN_CDDA.dll) used by Winamp.

    The vulnerability has been reported in version 5.05 and confirmed in version 5.06. Prior versions might also be affected, security firm Secunia warns. A proof of concept exploit was released yesterday by security outfit K-OTik. K-otik advises users to uninstall Winamp or at the very least disassociate .cda and .m3u extensions from Winamp until the bug is fixed.
    [/blockquote]

  2. #2

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    Ouch. I never used Winamp, I really don't use media players much. If this proves too much, I'll wait until a safer version is released for free.

  3. #3
    Товарищ Красный Master Trainer
    Master Trainer
    RedStarWarrior's Avatar
    Join Date
    Apr 2000
    Location
    Virginia, USA
    Posts
    8,036

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    Heh, I will continue to use Winamp. I don't have any files run on my system without my express permission. This security vulnerability doesn't really seem that harmful to me.
    THE MOST AWESOME GUY ON THE FORUMS!!

    Winner of the 2009 Zing, the 2010 Пролетарии всех стран, соединяйтесь!, the 2011 Conventioneers, the 2012 Me loved ponies first, and the 2013 Cool Unown Awards

    "Judge if you want. We are all going to die. I intend to deserve it." - A Softer World

  4. #4
    Banned
    Join Date
    Jun 2003
    Posts
    1,521

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    I don't use Winamp anyway, and here's a nother reason not to do so again. I always use Windows Media Player now. I think Winamp sucks anyway, WMP is like the only program that Microsoft can make correctly.

  5. #5
    Banned
    Join Date
    Jan 2004
    Posts
    718

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    [blockquote]
    Moonlight Espeon said:
    WMP is like the only program that Microsoft can make correctly.
    [/blockquote]don't forget that they're the masterminds behind the award-winning Halo series (I have not and do not plan on playing Halo)

  6. #6
    Moderator
    Moderator
    kainashi's Avatar
    Join Date
    Apr 2000
    Location
    Detroit, MI
    Posts
    21,260

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    oh dear. hope it's fixed soon.

  7. #7
    Moderator
    Moderator
    kainashi's Avatar
    Join Date
    Apr 2000
    Location
    Detroit, MI
    Posts
    21,260

    Default WARNING: Extremely Critical Winamp vulnerability discovered

    winamp 5.07 released

    awesome. :monocle: should be on the front page of winamp.com soon.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •