English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Winamp "NowPlaying" Unspecified Vulnerability


Secunia ID

SA31371

CVE-ID

CVE-2008-3567

Release Date

05 Aug 2008

Last Change

13 Aug 2008

Criticality

Moderately Critical

Solution Status

Vendor Patch

Software

Winamp 5.x

Where

From remote

Impact
Unknown

Covers various weaknesses, security issues, and vulnerabilities not covered by the other impact types, or where the impact isn't known due to insufficient information from vendors and researchers.

Description

A vulnerability with an unknown impact has been reported in Winamp.

The vulnerability is caused due to an unspecified error within the "NowPlaying" functionality. No further information is currently available.

The vulnerability is reported in versions prior to 5.541.

Solution

Update to version 5.541.

Winamp 5.541 Full (US English version):
http://download.nullsoft.com/winamp/client/winamp5541_full_en-us.exe

Winamp 5.541 Full (Multi-national installer):
http://download.nullsoft.com/winamp/client/winamp5541_full_all.exe

Winamp 5.541 Pro:
http://download.nullsoft.com/winamp/client/winamp5541_pro_all.exe

Winamp 5.541 Lite:
http://download.nullsoft.com/winamp/client/winamp5541_lite_en-us.exe

Reported by

Reported by the vendor.

Original Advisory

http://forums.winamp.com/showthread.php?threadid=295505