| Home Forum Radio Memberlist Help Search Quick Links |
| Forum Index » Internet » Security Alerts and vulnerabilities » Winamp vulnerability |
| Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here.. |
![]() |
![]() |
|
Thread Tools | Display Modes | ![]() |
|
#1
|
||||
|
||||
|
A vulnerability has been reported in Winamp, which can be exploited by malicious people to compromise a user's system.
The problem is caused due to insufficient restrictions on Winamp skin zip files (.wsz). This can e.g. be exploited by a malicious website using a specially crafted Winamp skin to place and execute arbitrary programs. With Internet Explorer this can be done without user interaction. An XML document in the Winamp skin zip file can reference a HTML document using the "browser" tag and get it to run in the "Local computer zone". This can be exploited to run an executable program embedded in the Winamp skin file using the "object" tag and the "codebase" attribute. NOTE: The vulnerability is reportedly being exploited in the wild. The vulnerability has been confirmed on a fully patched system with Winamp 5.04 using Internet Explorer 6.0 on Microsoft Windows XP SP1. Solution: Update to version 5.05. http://www.winamp.com/player/ |
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| RSS-Microsoft Security Advisory (899480): Vulnerability in TCP Could Allow Connection Reset - 5/18/2005 | RSS Importer | Security Alerts and vulnerabilities | 0 | 05-18-2005 02:00 AM |
| WinAMP--Buffer Overflow Vulnerability | Mobo | Security Alerts and vulnerabilities | 0 | 01-28-2005 07:13 PM |
| Itunes Vulnerability | Mobo | Security Alerts and vulnerabilities | 0 | 01-14-2005 07:24 AM |
| Winamp vulnerability | Mobo | Security Alerts and vulnerabilities | 0 | 11-29-2004 04:26 PM |
|
|
||