Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Critical Winamp Buffer Overflow Vulnerability


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Critical Winamp Buffer Overflow Vulnerability
Reply
 
Thread Tools
Old 30-01-2006, 15:53   #1
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Critical Winamp Buffer Overflow Vulnerability

source: http://www.frsirt.com/english/advisories/2006/0361

Quote:
Advisory ID : FrSIRT/ADV-2006-0361
CVE ID : GENERIC-MAP-NOMATCH
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-01-29

Technical Description

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a buffer overflow error when processing a specially crafted playlist (".pls" file) containing a malformed "File1" tag, which could be exploited by remote attackers to execute arbitrary commands and take complete control of an affected system without any user-interaction via a specially crafted web page.

Exploits

http://www.frsirt.com/exploits/20060...namp0day.c.php

Affected Products

Nullsoft Winamp version 5.12 and prior

Solution

The FrSIRT is not aware of any official supplied patch for this issue.

Workarounds

To prevent opening malicious files automatically, FrSIRT recommends :

Disabling the "audio/scpls" and "audio/mpegurl" MIME Types in Internet Explorer by deleting or renaming the following registry keys :
"HKEY_CLASSES_ROOT\.pls" and "HKEY_CLASSES_ROOT\.m3u".

And disassociating the "pls" and "m3u" file extensions in Windows :

- Launch Windows Explorer
- On the Tools Menu select "Folder Options"
- Select the "File Types" tab
- Scroll to find the PLS and M3U file extensions and then press the "Delete" button

References

http://www.frsirt.com/english/advisories/2006/0361
http://www.frsirt.com/exploits/20060...namp0day.c.php
I'm guessing that quite a few of us use Winamp. Not sure what AOL's policy is regarding patching, especially as I thought that they had discontinued development/support for Winamp.
Gareth is offline   Reply With Quote
Old 30-01-2006, 18:10   #2
cf.addict
 
Down the Pub's Avatar
 
Join Date: Jan 2006
Location: Widnes
Services: V+/vbox - BT Anytime - O2 16meg (for now, when it goes live until then vm 20meg)
Posts: 437
Down the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud ofDown the Pub has much to be proud of
Re: Critical Winamp Buffer Overflow Vulnerability

i used to ad was pretty good but became a bit of a pain now got...................media monkey and like winamp.....it's free.........

http://www.download.com/MediaMonkey/...ml?tag=lst-0-2
Down the Pub is offline   Reply With Quote
Old 31-01-2006, 16:03   #3
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Critical Winamp Buffer Overflow Vulnerability

Fixed already... now that's impressive Good job, nullsoft

version 5.13 is now available from http://www.winamp.com/player/ or http://www.winamp.com/in_mp3.dll is the fix.
Gareth is offline   Reply With Quote
Old 02-02-2006, 06:25   #4
cf.mega poster
 
Join Date: Sep 2003
Location: Leics
Age: 29
Services: none
Posts: 5,638
Chrysalis has reached the bronze age
Chrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze ageChrysalis has reached the bronze age
Re: Critical Winamp Buffer Overflow Vulnerability

thanks
Chrysalis is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 06:11.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)