Winamp blighted by bug brace
Lament over Ultravox vuln
Posted in Software & Security, 21st January 2008 15:49 GMT
Free whitepaper – What Exchange can't do - and Dell can
A brace of bugs in Winamp pose a serious security risk for users of the popular media player package, security watchers warn.
The buffer overflow-related flaws in Winamp 5.x create a means for hackers to take over vulnerable systems. Flaws in a library (in_mp3.dll) involved in parsing Ultravox streaming metadata open up the door to abuse, security notification firm Secunia warns. "These boundary errors can be exploited to cause stack-based buffer overflows via overly long '<artist>' and '<name>' tag values in the <metadata> section," it explains.
Secunia, whose researchers discovered the bugs, adds that successful exploitation allows the execution of arbitrary code. The vulnerabilities have been confirmed in versions 5.21, 5.5, and 5.51 of Winamp. Other versions may also be affected.
Users are advised to upgrade to Winamp version 5.52. Winamp is developed by Nullsoft, a subsidiary of AOL Music. ®
Free whitepaper – Managing desktop software for fun and profit
The Register Agile Data Center Summit
New storage architectures make SSDs more cost-effective
Dell PowerEdge R710 solution with VMware ESX vs. Dell PowerEdge 2850 solution

Sign up, sign up for The Register IT security newsletter
Microsoft's Windows 7 price gamble - and why it's flawed
Managing Desktop Software for fun and profit
Intel's flash new SSDs hit by bugs