also @ TechSpot: UK's SOCA seizes domain of popular music blog, rnbxclusive.com
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Download Now:

Critical bug found in WinAMP

Thread Tools Search this Thread
  #1  
Old 04-06-2004
Julio's Avatar
TechSpot Executive Editor
 
Location: Ecuador
Member since: Feb 2002, 5,355 posts
System specs
Critical bug found in WinAMP

According to TechWorld, a "highly critical hole" found in the popular media player, WinAMP, can open a window to hackers that only by running Fasttracker 2 ".xm" media files through a malicious website... We recommend upgrading to the latest version of the player inmediately.

It is possible to cause a heap overflow and so run code on the person's system. A ".xm" file is not needed however, as the software runs through all supported files with the same faulty piece of code. This greatly increases the opportunities hackers may have to con someone into clicking a link and so providing them with system access.
  #2  
Old 04-06-2004
Per Hansson's Avatar
TechSpot Server Guru
 
Location: Sweden
Member since: Feb 2002, 1,513 posts
System specs
Umm, does version 5.03 (latest) solve the issue then?

I did not see it in the changelog....
__________________
"The one who says it cannot be done should never interrupt the one who is doing it."
  #3  
Old 04-06-2004
Julio's Avatar
TechSpot Executive Editor
 
Location: Ecuador
Member since: Feb 2002, 5,355 posts
System specs
According to TechWorld website it does. All previous versions including 2.x are vulnerable.
  #4  
Old 04-06-2004
Didou's Avatar
Bowtie extraordinair!
 
Location: Brussels, Belgium
Member since: Feb 2002, 5,895 posts
System specs
XMMS
  #5  
Old 04-06-2004
BrownPaper's Avatar
TechSpot Booster
 
Location: Los Angeles, CA USA
Member since: Feb 2003, 467 posts
System specs
i guess all those people who want to stick with winamp 2.xx will have a really good reason to upgrade to winamp 5.xx. just use the classic winamp 2.xx style skins if you do not like the newer winamp3 style skins.

didou, xmms would be good but most people are running windoze.
  #6  
Old 04-06-2004
StormBringer's Avatar
TechSpot Evangelist
 
Location: USA
Member since: Apr 2002, 2,871 posts
Wow, Fasttracker is a blast from the past. I used to love tinkering with modules.

On a sad note, guess I'll be looking for a new mp3 player. I had gone back to 2.xx because Winamp 5.x was so bloated and such a hog. Quite a sad day, I've been a loyal user of Winamp since before the first release went public.
  #7  
Old 04-06-2004
SNGX1275's Avatar
TechSpot Forces Special
 
Location: Rolla, Missouri, USA
Member since: Feb 2002, 10,815 posts
System specs
So unless you are on some shady website and decide to click some audio link they have - you won't get affected right? Seems to me thats easy enough to avoid.

/me sticks with Winamp 5.0superearlyalphaness:
  #8  
Old 04-13-2004
SNGX1275's Avatar
TechSpot Forces Special
 
Location: Rolla, Missouri, USA
Member since: Feb 2002, 10,815 posts
System specs
Ok my post above this was made without fully looking into the problem. But upon further investigation it appears my above comment was incorrect. This link explains to me what I didn't read first. But it also contains this important piece of information if you for any number of reasons don't want to upgrade your winamp, and don't use any Fasttracker files.
Quote:
If for some reason it is impossible to download the updated version of
Winamp, the vendor has informed NGSS that it is possible to disable the
handling of Fasttracker 2 module files by taking the following steps:

1. Right click the Winamp player, go to 'Options' and then to
'Preferences...'.

2. In the new window which loads, go to 'Plug-ins' and 'Input'.

3. Look for the input plug-in items 'Nullsoft Module Decoder' and double
click it to bring up the 'Nullsoft Module Decoder Preferences' window.

4. Select the 'Fasttracker 2' loader and deselect the 'Enabled' checkbox to
the right of the loaders list.

5. Close all of the option windows and return to the main player.
Closed Thread

Similar Topics
Topic Replies Forum
Internet not working, computer says no networks found, cmd not found 3 Virus and Malware Removal
Critical vulnerability found in Adobe Flash Player 6 TechSpot News and Comments
Critical vulnerability found in in JPEG Processing 1 General Discussion
Critical vulnerabilities found in WinZip tool 0 General Discussion
Critical vulnerability found in WinAMP 1 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 03:45 AM.