Critical Security Flaw in Winamp

r0x0r

A recent discovery of a security flaw in Winamp has been handled exceptionally fast from the Nullsoft guys. A new version of the player has been released which fixes the previous issues and leaves you feeling all warm and fuzzy inside.

The Problem:

AtmaCA has found an extremely critical security hole in AOL’s Winamp and a publicly available exploit is being reported.

The flaw is caused by a boundary error during the handling of filenames including a computer name, says Secunia, going on:

“This can be exploited to cause a buffer overflow via a specially crafted playlist containing a filename starting with an overly long computer name (about 1040 bytes).

The Solution:

Winamp 5.13

via MP3newswire.net

One Response to “Critical Security Flaw in Winamp”

  1. If someone’s interested in further color-related resources, here’s a good site

Leave a Reply