This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Winamp updates/advisories

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Winamp v5.57 released
- http://secunia.com/advisories/37495/2/
Last Update: 2009-12-18
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: Winamp 5.x …
Solution: Update to version 5.57.
http://www.winamp.com/media-player

- http://www.winamp.com/help/Version_History…71_.28Latest.29

- http://www.theregister.co.uk/2009/12/21/winamp_update/

:ph34r:
FYI…

Winamp v5.6…
- http://secunia.com/advisories/42004/
Release Date: 2010-11-30
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Solution: Update to version 5.6.
Original Advisory: Winamp:
http://forums.winamp.com/showthread.php?threadid=159785

- http://www.winamp.com/media-player/en
Winamp 5.6, Build 3080 (5.6.0.3080)

- http://www.winamp.com/help/Version_History….6_.28Latest.29

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2586
CVSS v2 Base Score: 9.3 (HIGH)
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4370
CVSS v2 Base Score: 9.3 (HIGH)
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4371
CVSS v2 Base Score: 9.3 (HIGH)
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4372
Last revised: 12/03/2010
CVSS v2 Base Score: 9.3 (HIGH)
"… before 5.6 …"

:ph34r:
FYI…

Winamp v5.601 released
- http://secunia.com/advisories/42475/
Release Date: 2010-12-07
Criticality level: Moderately critical
Impact: Unknown
Where: From remote
Solution Status: Vendor Patch
… The vulnerability is reported in versions prior to 5.601.
Solution: Update to version 5.601.
Original Advisory: http://forums.winamp.com/showthread.php?s=…threadid=159785

- http://www.winamp.com/help/Version_History…01_.28Latest.29
___

- http://secunia.com/advisories/44600/
Release Date: 2011-05-16
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
"… vulnerability is confirmed in version 5.61. Other versions may also be affected…"

- http://www.winamp.com/help/Version_History#Winamp_5.61

:ph34r:
FYI…

Winamp v5.62 released
- http://www.winamp.com/media-player/en
30 June 2011

- http://forums.winamp.com/showthread.php?t=332010
Winamp 5.62, Build 3161 (5.6.2.3161) - 30 June 2011
- http://www.winamp.com/help/Version_History#Winamp_5.62
___

- http://secunia.com/advisories/45028/
Last Update: 2011-07-05
Criticality level: Highly critical
Impact: System access
Where: From remote…
… The vulnerability is confirmed in version 5.6. Other versions may also be affected.
Solution: Update to version 5.62.

- http://secunia.com/advisories/44600/
Solution: Update to version 5.62.

:ph34r: :ph34r:
FYI…

Winamp v5.623 released
- http://forums.winamp.com/showthread.php?t=332010
9 Dec 2011
Winamp 5.623
* Fixed: mp3 decoding errors at end of file (should fix reported CD burning errors)
* Fixed: [aacdec] Detection of parametric stereo for AAC files made with older encoders
* Fixed: [enc_fhgaac] MP4 encoder not always closing on errors or aborted transfers
* Fixed: [in_avi] Crashing with certain malformed AVI files
* Fixed: [in_flac & in_mp4] Memory leaks
* Fixed: [in_mod] Bounds check for comments parsing
* Fixed: [pmp] Multithreaded race condition (now supports thread-safe transfers)
* Fixed: [pmp_android] Embedded album art being deleted on transfers
* Misc: More general tweaks, improvements, fixes and optimizations
* Updated: [enc_fhgaac] Fraunhofer AAC Encoder v3.2.4
* Updated: [gen_jumpex] JTFE v1.2.5…

- http://www.securitytracker.com/id/1026404
Dec 12 2011
CVE Reference: CVE-2011-3834
Impact: Execution of arbitrary code via network, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version: 5.622; possibly prior versions…
Solution: The vendor has issued a fix (5.623)…
… The original advisory is available at:
http://secunia.com/secunia_research/2011-81/ || https://secunia.com/advisories/46882/
Rating: Highly critical
Impact: System access
Where: From remote…
Solution: Update to version 5.623.
Dmitriy Pletnev of Secunia Research reported this vulnerability…

- http://h-online.com/-1394031
12 December 2011

:ph34r:

FYI…

Winamp ends - 12.20.2013 …
- http://www.winamp.com/media-player/en
"Winamp.com and associated web services will no longer be available past December 20, 2013. Additionally, Winamp Media players will no longer be available for download. Please download the latest version before that date. See release notes for latest improvements to this last release. Thanks for supporting the Winamp community for over 15 years."
 

:(