Highly critical vulnerability discovered

May 1, 2007 19:16 GMT  ·  By

Winamp is surely the most famous audio player in the entire world because it is currently installed on millions of computers. However, the popularity doesn't necessarily mean the program is also secure and safe to use as a new vulnerability was discovered in the application. Security company Secunia reported that a security flaw exists in the audio player that might allow an attacker to connect and control an affected computer. It seems like the vulnerability was confirmed only in version 5.34 but other releases might be also affected and can harm your computer.

"Marsu has reported a vulnerability in Winamp, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error within the handling of MP4 files and can be exploited to cause memory corruption via a specially crafted MP4 file. Successful exploitation allows execution of arbitrary code," Secunia sustained in the security advisory.

The solution? Avoid opening untrusted MP4 files because the attacker might use the malicious file to exploit the vulnerability. However, the security flaw will be probably fixed in an upcoming version of Winamp so you should wait for a while before opening anonymous MP4 files.

It's obvious that the security of our computers is more threatened by almost any vulnerability discovered in the applications installed on the systems. In the past, the attackers managed to find flaws even in our compression tools, WinZIP being one of the affected applications. However, you should try to stay up-to-date with the latest security advisories concerning your installed programs. If you want to download the latest version of Winamp, you can find it on Softpedia, available for free.