Results 1 to 6 of 6

Thread: Highly Critical Hole In Winamp

  1. #1
    WinAmp music to hackers' ears

    "highly critical" hole in one of the most-used pieces of software in the world means that audio files will be music to hackers' ears.

    The ubiquitous WinAmp program - used to play a huge range of media files - can provide someone with system access simply by getting someone to visit a malicious website. It all has to do with how the software loads Fasttracker 2 ".xm" media files.

    It is possible to cause a heap overflow and so run code on the person's system. A ".xm" file is not needed however, as the software runs through all supported files with the same faulty piece of code. This greatly increases the opportunities hackers may have to con someone into clicking a link and so providing them with system access.

    The flaw affects all WinAmps and so the only advice is to upgrade as soon as possible to the new patched version (5.03)

    WinAmp in its various forms has been downloaded tens of millions of times and has a huge installed base. It can deal with 30 different file types and has hundreds of plug-ins.

    The hole was found by NGSSoftware and you can find out a lot more about it, plus details to fill in the hole without having to upgrade here

  2. Software & Hardware   -   #2
    Poster
    Join Date
    Jan 2004
    Posts
    3,073
    /me pats QCD Player on the head
    On a given day or given circumstance, you think you have a limit.
    And you then go for this limit and you touch this limit and you think "Ok, this is the limit".
    As soon as you touch this limit, something happens and you suddenly can go a little bit further.
    With your mind power, your determination, your instinct and the experience as well, you can fly very high.

    - Ayrton Senna, R.I.P.

  3. Software & Hardware   -   #3
    Originally posted by 4th gen@6 April 2004 - 12:23
    /me pats QCD Player on the head
    Or FOOBAR ( my case )

  4. Software & Hardware   -   #4
    again i cant understand why ppl would surf with those internal web browsers, like in the kliteapp and win amp ect

    why do ppl think its taken so long to get even IE close to being right

    my advise is never use in app browsers at all man

  5. Software & Hardware   -   #5
    Mullyman's Avatar Poster
    Join Date
    Jan 2004
    Location
    Canada
    Posts
    232
    Why don"t you just post the site and give credit to the person who wrote the article..instead of coping it

    http://www.techworld.com/security/ne...fm?NewsID=1343
    DEMO'S WORLD
    Knowledge And Wisdom Are Gained By Listening And Observing And Knowing When To Keep Your Fucking Mouth Shut!!!!

  6. Software & Hardware   -   #6
    uNz[i]'s Avatar Out of order
    Join Date
    Mar 2003
    Posts
    2,217
    Another feckin' update?
    Maybe I'll upgrade on the weekend.. this'll do till then...

    Originally posted by SH's link
    it is possible to disable the handling of Fasttracker 2 module files by taking the following steps:

    1. Right click the Winamp player, go to 'Options' and then to 'Preferences...'.

    2. In the new window which loads, go to 'Plug-ins' and 'Input'.

    3. Look for the input plug-in items 'Nullsoft Module Decoder' and double click it to bring up the 'Nullsoft Module Decoder Preferences' window.

    4. Select the 'Fasttracker 2' loader and deselect the 'Enabled' checkbox to the right of the loaders list.

    5. Close all of the option windows and return to the main player.
    Thanks for the heads up SH.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •