This article is more than 1 year old

Winamp mends trio of old-school security holes

Heap overflow? Winamp? Party like it's 1999

An update to Winamp closes a terrible trio of critical security holes in the popular media player application.

The rather old-school vulnerabilities involve a brace of integer overflow cockups in the in_avi.dll plug-in and a heap-based buffer overflow vulnerability in the in_mod.dll plug-in library. All three flaws create a means to inject hostile code into systems running vulnerable versions of the software, which is developed by Nullsoft, a division of AOL Music. Exploits would involve tricking victims into attempting to play malformed media files.

Users are advised to upgrade to version 5.623 of Winamp media player for Windows, as explained in an advisory by security notification firm Secunia here. More details can be found in a post on Winamp's forums here. ®

More about

TIP US OFF

Send us news


Other stories you might like