News Serious hole in Winamp stays unfixed

Discussion in 'Article Discussion' started by GreatOldOne, 24 Nov 2004.

  1. GreatOldOne

    GreatOldOne Wannabe Martian

    Joined:
    29 Jan 2002
    Posts:
    12,092
    Likes Received:
    112
    A flaw that was thought to be fixed is still wipping the llama's ass, according to the Inq:

    A REPORT FROM security firm Secunia described a hole in Winamp as "highly critical".

    The hole, reported by Brett Moore, describes a boundary error which can be used to deceive users into going to a malicious web site.

    The problem occurs with versions 5.05 and 5.06.

    However, Brett Moore, the finder of the hole, said that although there's a patched version available, that doesn't fix the buffer overflow problem.

    A temporary solution to the problem is to dissociate .CDA and .M3U file extensions from the software.


    L'inquage, with further links to the report and Brett's latest notice on the flaw.

    Thing is, with AOL euthanizing Nullsoft, will this hole ever be fixed?
     
Tags: Add Tags

Share This Page