« Previous Post
Next Post »

Critical Bug Found In Winamp 5.34



WinampDanish vulnerability tracker Secunia and eEye Digital Security of California have discovered a flaw in the Winamp 5.34 plugin that decodes MP4 files. It seems that an attacker could compromise a computer by feeding a specially made MP4 file to the player. This would allow the attacker to execute malicious code remotely. According to eEye’s alert:

“A media player remote code execution vulnerability has a very high impact since the source of the malicious payload can be any site on the Internet. An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with administrator credentials.”

While we wait for a patch from Nullsoft, a simple way to prevent this is to disassociate the .mp4 extension from Winamp by going to Options -> Preferences, then General Preferences -> File Types and deselecting MP4.

Technorati Tags: ,

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Netvouz
  • DZone
  • ThisNext
  • MisterWong
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Furl
  • Fark
  • Wists
  • Technorati
  • Reddit
  • SphereIt
  • Bumpzee
  • Netscape
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...



Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.


Subscribe without commenting


Leave a Reply


Note: Any comments are permitted only because the site owner is letting you post, and any comments will be removed for any reason at the absolute discretion of the site owner.


This blog uses the CommentLuv plugin which will try and parse your sites feed and display a link to your last post, please be patient while it tries to find it for you. A link to the plugin can be found in the sidebar under Featured Sites.