Skip to navigation
Latest News

WinAmp vulnerability highlighted for handling of playlists

By Steve Malone

Posted on 26 Nov 2004 at 17:09

Another hole in the once popular WinAmp has been discovered.

The latest breach, following separate discoveries in August and April, remains unpatched and could lead to an attacker accessing the system remotely and running code.

Brett Moore, of Security-Assessment.com, who discovered the flaw, writes that a boundary error in the 'IN_CDDA.dll' file could be exploited with a buffer overrun attack if a user was persuaded to visit a website containing a specially crafted '.m3u' playlist. This would download and run automatically, without the victim having to explicitly click on anything on the malicious website.

Currently, security experts advise WinAmp users to disassociate files with .cda and .m3u extensions from the player.

Secunia has upgraded its severity rating for this flaw to Extremely Critical.

The flaw affects versions 5.05 and 5.06 of the player.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.