February 3rd, 2006

Running Winamp? Don’t Play Any Strange Playlists

By Jimmy Daniels
Contributing Writer, RealTechNews

On Monday Nullsoft announced that version 5.12 had a security bug and released a patch to fix it. Exploit code is already circulating the internet, a rep from Sunbelt Software said they have already found websites hosting a winamp play list that took advantage of the exploit to load spyware on their computer.

“After surfing to a malicious Web site on our test machines, the file ‘x.pls’ begins to download,” Sunbelt’s Adam Thomas wrote in a posting on the anti-spyware software maker’s corporate blog. “Almost immediately, Winamp starts to execute the play list and remote code execution begins.”

The flaw was disclosed on Monday, when Winamp maker Nullsoft, a division of America Online, released an update to fix it. The company posted version 5.13 of Winamp, while Secunia and other security companies issued alerts about the problem. Secunia rated the issue “extremely critical,” its highest rating.

“Not following the recommendation from Nullsoft to upgrade to version 5.13 could result in the extremely nasty CWS Looking-For.Home Search Assistant infection as well as an installation of our good friend SpySheriff,” Thomas wrote. Antivirus software is not yet detecting this exploit, he wrote.

We Say: Download the latest version here if you use Winamp and save yourself some trouble. SpySherriff is definitely a pain to remove, my boys pc got hit with it from the windows meta file exploit, changed his background, flashed this warning every minute or so. I hated them in less than a minute, a new record. At least the website Sunbelt found was no longer available as of this writing.

Share and Enjoy:These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • digg
  • Fark
  • NewsVine
  • Reddit
  • YahooMyWeb
You can leave a comment, or trackback from your own site. RSS 2.0

One comment to "Running Winamp? Don’t Play Any Strange Playlists"

  1. Katia sousa says:

    I have download a few versions of winamp including the latest one and let me tell you isnt good,now i install the version 5.13,i will try…the other stuck

    June 17th, 2008 at 5:23 am

Leave a comment