PDA

View Full Version : Winamp Computer Name Handling Buffer Overflow Vulnerability


ronjor
January 30th, 2006, 06:47 AM
{QUOTE-> Extremely critical

Impact: System access
Where: From remote
Solution Status: Unpatched

NOTE: An exploit is publicly available.

Solution: Use another product.
<-QUOTE}
Secunia (http://secunia.com/advisories/18649/)

ronjor
January 30th, 2006, 05:40 PM
New version. Update Alerts (http://www.wilderssecurity.com/showthread.php?p=670995)

thanx
February 1st, 2006, 01:34 AM
Thanx Ronjor, I updated. :)

Tan
February 1st, 2006, 01:39 AM
what does this mean if i still run 2.75 and only listen to music that i have locally on my hard drive?

ronjor
February 4th, 2006, 11:31 AM
Spyware tunnels in on Winamp flaw

{QUOTE-> Earlier this week, security companies warned that attack code for exploiting the flaw was circulating on the Internet. On Thursday, Sunbelt Software said it had found a Web site hosting a malicious Winamp playlist file. Opening the file loads spyware onto an unwitting user's PC, it said.
<-QUOTE}
Story (http://news.zdnet.com/2100-1009_22-6035188.html)