Winamp security vulnerability [Archive] - Quintessential Forum

PDA

View Full Version : Winamp security vulnerability


jkrzok
08-26-2004, 02:28 PM
Yet another reason to switch from Winamp:

http://secunia.com/advisories/12381/

A vulnerability has been reported in Winamp, which can be exploited by malicious people to compromise a user's system. The problem is caused due to insufficient restrictions on Winamp skin zip files (.wsz). This can e.g. be exploited by a malicious website using a specially crafted Winamp skin to place and execute arbitrary programs. With Internet Explorer this can be done without user interaction. An XML document in the Winamp skin zip file can reference a HTML document using the "browser" tag and get it to run in the "Local computer zone". This can be exploited to run an executable program embedded in the Winamp skin file using the "object" tag and the "codebase" attribute. NOTE: The vulnerability is reportedly being exploited in the wild. The vulnerability has been confirmed on a fully patched system with Winamp 5.04 using Internet Explorer 6.0 on Microsoft Windows XP SP1.

Solution: Use another product.

appurve
08-26-2004, 06:03 PM
Thanx for tellin man.But who cares , i use QCD. Why settle for less when you can get the best. But still i think it might help few peeps with winamp.

hedge
08-27-2004, 09:05 AM
Yeah allegedly 5.05 is gonna fix the opening of .exe's from within the skin files... why the hell that would be possible in the first place is beyond me tho.

Young Twig
08-27-2004, 05:31 PM
Heh... Two posts on the same thing.

Toe
08-29-2004, 04:51 PM
Solution: use QCD.
Fixed.

Rex_Mundi_Incarnit
02-06-2006, 10:47 PM
*resurrect*

There is a new security vulnerability with winamp. Read here (http://www.zdnetasia.com/news/security/0,39044215,39310016,00.htm) more about it. Basically "a security bug in Winamp is being exploited by miscreants to install spyware on machines running the media player software, experts have warned." Nice...:P

Tokelil
02-06-2006, 10:58 PM
Winamp has been removed from all my university's computers because of this. You now need special rights to install Winamp :evil:

Inthewoods
02-07-2006, 12:19 AM
Did anybody read the article? It's already been fixed in WA 5.13, released a week ago.

rorythedog
02-07-2006, 12:28 AM
Did anybody read the article? It's already been fixed in WA 5.13, released a week ago.

Damn. Off to Torrentspy again! :cry:

Todd The Kiwi
02-07-2006, 06:04 AM
Winamp has been removed from all my university's computers because of this. You now need special rights to install Winamp :evil:ahem, you guys should be studying mate =)