Critical Security Flaw Found in Winamp

By Nate Mook | Published January 30, 2006, 12:37 PM

UPDATED An "extremely critical" security vulnerability has been discovered in AOL's Winamp digital media player, relating to the way the software handles filenames that include a computer name. An exploit has already surfaced for the flaw, which affects version 5 of the software.

By late Monday, Winamp developers had already released version 5.13 of the software, which plugs the security hole.

According to an advisory by Secunia, the vulnerability "can be exploited to cause a buffer overflow via a specially crafted playlist containing a filename starting with an overly long computer name." A successful attack can lead to arbitrary code being run on a user's computer.

The problem was first reported alongside the exploit created by ATmaCA, and utilizes a specially crafted playlist file to overflow Winamp. The PLS file can simply be loaded remotely through an IFRAME on a Web site.

This isn't the first critical vulnerability to hit AOL's popular player. Last July, a bug was discovered in Winamp's handling of ID3v2 tags. That issue also involved a buffer overflow that could have led to a remote system compromise, but it required some user interaction.

Comments

View comments by with a score of at least

I think winamp version 3 and about just over done. Why not just stay as a basic music player. I still using 2.64, and it serve me well. Version 5 just over kill and it lags when go from song to song when you have a list of hundreds of songs.

Score: 0

|

Running latest version of Winamp (v5.13) on my Pentium II 266mhz laptop running Windows Server 2003, playing a a list of over 50 songs and Windows Task Manager reports a CPU usage between 1-4% and a memory usuage ranging from only 2,560k - 3,664k running a classic Winamp v2.0 Skin.

This is exactly why i love Winamp & have always loved Winamp since i first installed it back in 1998, it does its job with lots of features/options to choose from & does it with minimum fuss and system resources.

My deal has always been this:

WMP for video.
Winamp for music.

My choice of formular for the past 8 years & it has never let me down. Winamp has always been s*** at video, i don't know why they even bothered other then they was bored.

To be quite frank, i can't believe AOL hasn't completely bloated this thing to high heavens yet!

Fingers crossed, they never will.

Score: 0

|

PII? Dude, this is the 21st century.

Score: 0

|

totally... time to overclock it to 300!

Score: 0

|

lmao, you would be shocked how much a pentium II can actually do!

I dug it out of the attic a year or so ago, and with a 5GB hd and 192mb ram, I've got it running Windows Server 2003, full office applications, playing gigs of music, porn, wireless internet.

It's a little slow at multi-tasking obviously, but seriously, a lot of today's computers power is purely for gaming and video editing.

Score: 0

|

I stopped using that POS when they decided to make a non-skinned version of it take longer to open than WMP, and take just as long to open as iTunes. If iTunes worked with WMA files and could handle most video types, I'd use that solely, but for now I use three of them and am very happy. To hell with AOL and to hell with Winamp

Score: 0

|

Good don't use it. winamp is the best. Period. Obviously you have a problem, the rest of us Winamp lovers don't.

Score: 0

|

the version 3.x series was just horrible, after they released the 5.x series it was more like the old winamp again, but with the media lib, which is really nice.

Score: 0

|

Might I suggest www.9412.com for Classic Rock That Matters? The station's been around for over 6 years and have live dj's.

oh yeah - they got a chat room and message board too... along with 15,000 songs in the music library.

Score: 0

|

relevance?

Score: 0

|

SPAM!!

He is advertising, maybe he gets a kick back.

Score: 0

|

Winamp 5 with MMD3 skin and i am a happy camper. Other media players can't touch it.

Score: 0

|

What about XMPlay with the MMD3 skin? =)

Score: 0

|

Like the man said, other media players can't touch it...

Winamp is king, get used to it.

Score: 0

|

Winamp 5 Full 5.13, the now-fixed version, is available here at FileForum for download. (That was fast!)

And, I'll likely be using Winamp until they pry it from my cold dead hands. I continue to try others (e.g., JetAudio, Quintessential, etc.), but always seem to come back to good old Winamp. If nothing else, its auto-stop for incoming Skype calls will keep it in the running for me. (And if there are other players that do that, I'd very much like to know what they are. TIA.)

Score: 0

|

2.95 is still, by far, the champ.

Score: 0

|

ok i guess i'll use it then just let me open winamp 5 and make it a classic skin.. there now i have winamp 2.9x on my PC

Score: 0

|

While you're skinning your latest unsafe code, just know that you're just pretending to be 2.95. ;)

Score: 0

|

aaa yes, the good ole days. I believe I still have an installer for it. I may have to dig it up.

Score: 0

|

I'm using winamp 5.2 build 359 beta.

Works like a charm.

Score: 0

|

Good man.

Score: 0

|

Never used Winamp--well did on someone elses' computer for playing an mp3 once or twice but that's about it. Why learn something new when all I need is doable in WMP Classic and WMP 10? (yep I use MS, it's what I'm used to and it does what I want. Go ahead and bash away)

Score: 0

|

"yep I use MS, it's what I'm used to and it does what I want. Go ahead and bash away"

Hey, do what you wanna do, I'm sure you already know that MP Classic is not MS, and it is Open Source Software (OSS), and it does work pretty damned good :-)
http://sourceforge.net/projects/guliverkli/

Score: 0

|

Yes I did, however when I say "MP Classic" I am actually refering to Windows Media Player 6.4x from microsoft. I do use WMP Classic on my XP system when WMP10 can't play the 8-bit mono audio files (Why is that? Two different installs of XP PRO and one x64 bit edition and NONE of them can play the simple 8-bit mono .wav files), but my Win2k I stick with WMP 6.4. Yes the _original_ Windows 2000 CD (w/no service packs) came with WMP 6.4, and I love it.

Also love not having to install the bloat known as Sun Java--MS hasn't had a single exploit reported in msjava since a month before the lawsuit and my parent's Dell system can't stop getting errors with the blasted java plug in, no matter the version. Using XP Gold CD and then upgrading to SP2 (where msjava runtime stays on the system) I have yet to have any problems or errors that are Java related. Also no exploits.

Sorry for the tangeant just had to get that stuff outta my system...

Score: 0

|

How did you get a WinXP gold CD that has MS Java? I preordered WinXP directly from Microsoft before it came out and my copy of WinXP doesn't have MS Java on the CD. At the time it was an Install on Demand download in Internet Explorer 6.

Windows 2000 was the last version of Windows to include MS Java on the installation CD.

Score: 0

|

My Windows XP vanilla CD from 2002 does have MS Java engine.

Score: 0

|

If you're ordering it now, more-likely you'll get a XP cd with SP2 in it, which has JVM removed during the slipstream. But if you ordered the cd back in 2001 or 2002 before SP1 is out, then you'll get that JVM.

Score: 0

|

Technically, The whole SP1 vs SP1a is where MSJava disappeared. The original SP1 was only available for download a month before SP1a replaced it though--only saying it is possible a slipstreamed SP1 CD could have had msjava, but very unlikely as it was nuked once SP1a came out.

Score: 0

|

Depends on when you got it. There was a time when XP came with Java, then it was removed, then it was replaced. SP1 no java. There was even a java removal tool. There was a SP2, with no java about the time Sun decided MS could pay them to have it, SP2 official release has Java.

So depending on which version of XP you have, some have Java, some don't... So its possible.

Score: 0

|

winamp is by far my preferred player - hope all goes well for them with this.

Score: 0

|

How does this affect those of us that still prefer to stick with Winamp 2.9x?

Score: 0

|

I don't get how People say Winamp is outdated. I guess i can understand the media player thing but every other player out there now is like a fullscreen music player and I hate those kind.I love Winamp because it is so flexable and when AOL does finally kill it people will still be making plugins for it to keep it up to date.

Score: 0

|

People say Winamp is outdated because it isn't updated every week, and because it IS an old program. Winamp 5 is pretty damned good, and against the likes of Foobar2K and iTunes, that's quite an accomplishment.

I wish AOL would port the thing to OS X. Leaving Winamp (and its plugins) behind is one of the things preventing me from getting a Mac.

Score: 0

|

a operating system or a virus program I can understand but why would a media player need to be updated every week?

Score: 0

|

But then it really wouldn't be Winamp. They would have to call it Macamp.:)

Score: 0

|

Macamp is fine with me. I just want it on OS X.

Score: 0

|

Wow big surprise. Winamp was once a great audio player, but that was a long time ago...

Score: 0

|

foobar.

Score: 0

|

Winamp is still a great audio player.

Score: 0

|

2nd. Foobar is fast, clean, and lean, but you can pork it up to look nice & pretty if you like. Hasn't ever had any critical security flaws either as far as I know.

Score: 0

|

Obviously you don't keep up. winamp may have had early problems, but its been fixed. Its now the best media player..

Just because software didn't work a long time ago, doesn't mean it can't get better. Every software benefits from mistakes if they are smart.. Winamp has taken advantage of better technology, and its now the best.

Score: 0

|

"Secunia recommends the use of a different media player software for the time being, although users can mitigate any risk by not visiting any unknown Web pages."

Such a wordy sentence for saying its NOT a big deal. Not too many people aim to take advantage of vuln winamp users. People love winamp. Malicious users won't take advantage of users of software they like. So this is hardly a critical problem =\

Score: 0

|

Yeah, what's the point of exploiting vulnerabilities in really popular software?

Score: 0

|

Umm.. to ensure thay they are working properly? Duh!

What's the point of testing products, to make sure they work the way they are supposed to..

Problem solving isn't your strong suit is it?

Score: 0

|

A patched in_mp3 is available from
http://www.winamp.com/in_mp3.dll

Place this file in C:\Program Files\Winamp\Plugins.

An updated version of Winamp should be available by the end of the day.

Score: 0

|

Score: 0

|

Score: 0

|

Well, THAT was quick :)

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.