ALARM Group ALERT - click for a description of ALARM, The Computing Alert System Alert Number: 051707-03 Alert Date: 05/17/07 Alert Title: Updated version of Winamp addresses vulnerability Update-to: 050207-03 "Zero-day exploit for Winamp" OS/Platform/Application: Winamp < v5.35 on (potentially) all systems Category: UPDATE Severity: MEDIUM Attention: System Administrators/Users, Desktop Support Personnel, Winamp users |
Summary: An updated version (version 5.35) of AOL Music's popular Winamp media player has been made available to end users. Version 5.35 fixes a security vulnerability related to the handing of MP4 files that can result in remote code when a user opens a specifically-crafted MP4 file or message.
Recommended Actions: System administrators and Winamp users are encouraged to consider upgrading their Winamp players to version 5.35 at their earliest convenience.
ITS Actions: N/A
Resources:
Winamp download page (includes links to security bulletin
2007-05-15):
http://www.winamp.com/player/
Winamp support forums (discusses caveats, etc):
http://forums.winamp.com/forumdisplay.php?s=04d1bcbce11ee6d82bf13fca379ec745&forumid=11