Winamp users advisted to update to 5.03 due to critical hole find

A huge vulnerability has been found in Winamp which allows a specially crafted .xm file to cause a heap overflow and thus allow a hacker to run code on the unsuspecting user's machine.  All the hacker needs to do is lure a Winamp user into playing an infected .xm file or visiting a malicious website which contains the embedded infected .xm file.  Apparently other Winamp supported media files may also be used to launch an attack which may pose an issue for those downloading music from non-trusted sources such as through P2P software.

 

Winamp users are advised to upgrade to Winamp 5.03 which has patched this vulnerability.  It is not clear if this vulnerability affects just version 5 up to 5.02 or also its predecessors such as Winamp 2 or Winamp3. 

A "highly critical" hole in one of the most-used pieces of software in the world means that audio files will be music to hackers' ears.

The ubiquitous WinAmp program - used to play a huge range of media files - can provide someone with system access simply by getting someone to visit a malicious website. It all has to do with how the software loads Fasttracker 2 ".xm" media files.

It is possible to cause a heap overflow and so run code on the person's system. A ".xm" file is not needed however, as the software runs through all supported files with the same faulty piece of code. This greatly increases the opportunities hackers may have to con someone into clicking a link and so providing them with system access.

The flaw affects all WinAmps and so the only advice is to upgrade as soon as possible to the new patched version (5.03) on the company's website here.

WinAmp in its various forms has been downloaded tens of millions of times and has a huge installed base. It can deal with 30 different file types and has hundreds of plug-ins.

 

With the amount of hackers and even spammers exploiting vulnerabilities in Windows, it will be interesting to see if any take up the challenge of sharing infected music files. 

 

For the time being, I would recommend users stay clear of .xm 'FastTracker' files if they are just looking for music and also use the 'Save Target As...' right-click option on websites to avoid auto-running a potentially infected file.  If the website disallows Right-click, then treat the link as malicious unless you do not have Winamp installed or are using Winamp 5.03.

Source: Techworld.com

No posts to display