Winamp Updated to Fix Security Hole

AOL's Nullsoft division released a minor update to its Winamp digital audio player on Monday to correct a security vulnerability that could lead to buffer overflow and the potential execution of arbitrary code. Winamp 5.094 fixes the problem, along with a number of minor bugs.

The vulnerability lies in the way Winamp processes ID3 tags contained in MP3 files. If a malformed MP3 file is loaded into a playlist with an artist or title that is too long, it is possible to create overflow code that is later executed. The issue was reported to Nullsoft in late June, and an advisory was issued by LSS Security last week.

Comments are closed.

Why Trust Us



At BetaNews.com, we don't just report the news: We live it. Our team of tech-savvy writers is dedicated to bringing you breaking news, in-depth analysis, and trustworthy reviews across the digital landscape.

BetaNews, your source for breaking tech news, reviews, and in-depth reporting since 1998.

© 1998-2025 BetaNews, Inc. All Rights Reserved. About Us - Privacy Policy - Cookie Policy - Sitemap.