Click to go back to the index
Click to go back to the index DVD Hardware Reviews Storage Media Reviews Software Reviews
Click to go back to the index
Click to go back to the index
SanDisk Cruzer Titanium U3 2 GB   SanDisk Cruzer Titanium U3 2 G...
Memorex Mini Travel Drive U3 512 MB   Memorex Mini Travel Drive U3 5...
Verbatim Store N Go 512 MB   Verbatim Store N Go 512 MB
Maxell 16x DVD+R media review  Maxell 16x DVD+R media review
Fujifilm 16x DVD+R media review  Fujifilm 16x DVD+R media review
Verbatim 8x DVD-R Dual Layer review  Verbatim 8x DVD-R Dual Layer review
exPressit S.E.  exPressit S.E.
VSO ConvertXToDVD  VSO ConvertXToDVD
Firestreamer RM  Firestreamer RM

Security threat for Winamp users

  home - news

Posted on Monday 30th of January, 2006 at 18:53 by SirQUK
Source: CNet

Many readers of CDR-Zone.COM use Winamp on a regular basis as it is an easy to use and highly skinnable Media player. News from CNEt informs us that it might not be all that safe though and that an update to fix this is needed according to Secunia.

"The vulnerability is found in the latest version of Winamp 5.12. Earlier versions of the media player may also be affected, Secunia said.

Even though the security firm gave the vulnerability its highest rating for software threats, it noted that the number of people who use Winamp has declined over the years, so the scope of the problem is not as large as it once would have been.

"Winamp used to be the world's most popular MP3 player and is still quite popular, but as Windows Media Player has gotten better, some users have migrated over," said Thomas Kristensen, Secunia's chief technology officer.

Secunia is advising people to uninstall the player until America Online division Nullsoft, the maker of Winamp, develops an update for the flaw, especially as exploit code is circulating on the Internet.

"We aren't aware of any systems that have been compromised yet, but it's likely to happen since there's exploit code out," Kristensen said.

The vulnerability could be exploited when a Winamp user visits a malicious Web site and a tainted media file is launched onto the person's system. A buffer overflow is triggered, which allows the attacker to take control of the computer without being constrained by security measures, Kristensen noted.

The flaw was initially discovered by AtmacA.

The vulnerability is not the first to be found in the Winamp software. In late 2004, a highly critical flaw was found in the playlist files for the Winamp player. "

As mentioned in the story, no systems are known to be compromised as of yet but the threat still remains. Be warned!

*update*Nullsoft have released a new version, 5.13, to combat the security flaw. It comes in the three well known flavours, Full, Pro, Lite or visit their website.



Next Monday 30th at 18:53 Philips 16x DVD+R media review
Previous Monday 30th at 18:53 New ConvertXtoDVD Version 2.0
Software Tracker
   1. XoA YouTube Video Tools
   2. DVD43
   3. DVD Shrink
   4. Nero Mega Plugin Pack
   5. DVD Decrypter
News Tracker
  23:23 Slysoft Limited discount
  11:19 SlySoft's 5th Anniversary
  05:44 Slysoft Limited discount
  06:34 AnyDVD HD supports proact
  01:39 Slysoft offers a 20 proce
  01:32 AnyDVD HD now with BD+ su
  06:51 Slysoft offers a 20 proce
  20:40 Slysoft offers a discount
  20:18 1st anniversary SlySoft S
  20:55 OCZ preps SATA and SATAII
Guides Tracker
  05-11 GameJack v5.0.2.8 Quick G
  05-07 How to make a Photo DVD S
  04-25 DVDReMake Basic & Pro Opt
  04-13 Replace a modified menu s
  02-11 Autobypass Language Menu
Articles Tracker
  02-15 DVD Copy Software Roundup
  10-29 Interview with U3
  11-28 Recordable DVD Quality
  09-14 The High Definition DVD F
  01-06 List of ATAPI Error codes
Forum Tracker
 11-28 How to transfer songs fro
 11-29 DVDFab (Platinum/Gold/HD
 11-28 How to transfer songs fro
 11-25 First time it happened me
 11-25 update 39_167 for Wall_E
 11-24 Problem with burning
 11-23 DVDFab (Platinum/Gold/HD
 11-22 166 Out!
 11-21 codecs intsatlled on the
 11-21 Audio help please
Link Tracker
     Bitburners
     Burningbits
     Burnworld
     CDRInfo.COM
     CDRLab.pl
     DVD Copy Software
     DVD Writers
     Free Codecs
     K-Probe
     More links...