This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Winamp Vuln "...fixed version soon..."

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/16077/
Release Date: 2005-07-15
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Description: "…Successful exploitation allows execution of arbitrary code, but requires some user interaction (e.g. that the user adds a malicious MP3 file to a playlist and then plays the file). The vulnerability has been reported in versions 5.03a, 5.09, and 5.091. Other versions may also be affected.
Solution: The vendor will reportedly issue a fixed version soon…"

Current version is Winamp 5.093 ( Version History )
- http://www.winamp.com/player/version_history.php

Download
- http://www.winamp.com/player/free.php

:ph34r:
FYI…

- http://secunia.com/advisories/16077/
Solution: Update to version 5.094.

Winamp 5.094
- http://www.winamp.com/player/version_history.php
* Fixed: Security vulnerability in id3v2 tags
* Updated: new libmp4v2.dll
* New: New random number generation for playlist shuffle
* Fixed: Winamp now shuffles playlists larger than 32,768 songs
* Fixed: Fade on start now behaves properly
* Fixed: separate directsound settings with multiple instances
* Fixed: Winamp now supports adding URLs longer than 260 characters.
* Fixed: Editing files created in iTunes no longer causes corruption.
* Fixed: Length of long mp3's now reported properly
* Fixed: gen_jumpex no longer crashes when DEP is enabled
* Fixed: Sort selections in media library are now remembered.
* Fixed: Album names with non-alphanumeric character behave better
* Fixed: Fixed intermittent crash on seeking for some users
* New: in_wm now handles bitrate and length extended infov

:)