AplusWebMaster
Topic Starter
FYI…
- http://www.us-cert.gov/cas/bulletins/SB04-329.html#nullsoft
November 23, 2004
"…A vulnerability exists which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the 'IN_CDDA.dll' file. This can be exploited in various ways to cause a stack-based buffer overflow e.g. by tricking a user into visiting a malicious web site containing a specially crafted '.m3u' playlist. Successful exploitation allows execution of arbitrary code.
Update to version 5.0.6:
- http://www.winamp.com/player/
A Proof of Concept exploit has been published …"

- http://www.us-cert.gov/cas/bulletins/SB04-329.html#nullsoft
November 23, 2004
"…A vulnerability exists which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the 'IN_CDDA.dll' file. This can be exploited in various ways to cause a stack-based buffer overflow e.g. by tricking a user into visiting a malicious web site containing a specially crafted '.m3u' playlist. Successful exploitation allows execution of arbitrary code.
Update to version 5.0.6:
- http://www.winamp.com/player/
A Proof of Concept exploit has been published …"