All the latest UK technology news, reviews and analysis

Zero-day exploit exposes Winamp users

by Tom Sanders in California

31 Jan 2006

Be the first to comment

  • Tweet this

Winamp has published a security update to fix a critical vulnerability in its media player.

The move came after a security researcher known only as 'Kozan' discovered a flaw in Winamp 5.12 that could be exploited to compromise users' systems. Proof of concept code was published on Sunday. 

Attackers could exploit the flaw through a specially crafted playlist file. On opening the file the flaw results in a buffer overflow, allowing remote hackers to launch applications and take control of compromised systems.

The vulnerability effectively allows the attacker to turn the computer into a zombie system or steal data from the system's hard drive.

Security firm Secunia gave the flaw its most severe security rating of 'extremely critical'.

The free Winamp media player is owned by AOL, and the vulnerability has been confirmed only for version 5.12.

Users launching the application will automatically be prompted to update to version 5.13, an AOL spokesperson told vnunet.com. Alternatively they can download the updated application from the Winamp website.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Business Analyst - Telecoms

Business Analyst urgently required with a background...

Business Architect - Financial Services

We have an opportunity for an experienced Business Architect...

DBA - Unix Systems Support - Investment Management

Leading Institutional Investment Manager require an individual...

Senior Manager - IT Project Management - Fund Mgt

Leading Institutional Fund Manager require a Senior IT...

To send to more than one email address, simply separate each address with a comma.