This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Winamp 5.05 Vuln/fix Available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.us-cert.gov/cas/bulletins/SB04-329.html#nullsoft
November 23, 2004
"…A vulnerability exists which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the 'IN_CDDA.dll' file. This can be exploited in various ways to cause a stack-based buffer overflow e.g. by tricking a user into visiting a malicious web site containing a specially crafted '.m3u' playlist. Successful exploitation allows execution of arbitrary code.

Update to version 5.0.6:
- http://www.winamp.com/player/

A Proof of Concept exploit has been published …"

:ph34r:
Now on the Winamp site as of date/time of this post:

- http://www.winamp.com/player/version_history.php
"Winamp 5.07:
* Critical Security bug fixed in in_cdda.dll and .m3u handler
* in_mp3 & in_nsv should work on Win95 again
* Proxy settings work again
* Installer fixed so that read_file.dll is installed always with mod support
* Version number should be properly reported by IPC_GETVERSION for this build …"

Winamp 5.07 Player Download
- http://www.winamp.com/player/free.php

;)