Flaw affects versions 5.05 and 5.06
Flaw affects versions 5.05 and 5.06

Hackers exploit critical Winamp flaw

Media player vulnerability could allow execution of arbitrary code

Written by Robert Jaques

IT security experts have uncovered a critical vulnerability in the popular Winamp media player, which could be exploited by hackers to compromise a user's system.

Security expert Brett Moore, from Security-Assessment.com, published an advisory detailing the flaw. "The vulnerability is caused due to a boundary error in the 'IN_CDDA.dll' file," it stated.

"This can be exploited in various ways to cause a stack-based buffer overflow, e.g. by tricking a user into visiting a malicious website containing a specially crafted '.m3u' playlist."

Yesterday the threat level of the flaw was raised to 'critical' after the discovery of a hacker exploit which takes advantage of the vulnerability. Successful exploitation allows execution of arbitrary code, said Moore.

The vulnerability has been reported in version 5.05 and confirmed in version 5.06. Prior versions may also be affected, according to Moore, and the flaw has not been fixed in Winamp version 5.06 contrary to vendor statements.

The best workaround for the hundred of thousands of users of the media player is to disassociate '.cda' and '.m3u' extensions from Winamp.

Tags:

Further reading

Millions at risk from Java Virtual Machine flaw

Security experts predict imminent exploit   More...

Phishers use zombie nets to automate attacks

Anti-Phishing Working Group reports 'disturbing' new trend   More...

Tasin worms ate my Windows files

Newly intercepted mutants spreading rapidly   More...

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.   More...

Related articles

Critical flaw hits Yahoo Widgets

Vulnerability could allow attackers to run code   More...

OpenOffice hit by 'highly critical' flaw

Problems dealing with Tiff images could allow remote access   More...

Fedora patches old OpenOffice flaw

Two weeks after main sponsor Red Hat plugged the same hole   More...

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement