stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Winamp has extremely critical vulnerability







Winamp has extremely critical
vulnerability

Winamp has extremely critical
vulnerability
08/27/2004 01:56 PM

A vulnerability has been reported in Winamp, which can be exploited by malicious people to compromise a user's system.

The problem is caused due to insufficient restrictions on Winamp skin zip files (.wsz). This can e.g. be exploited by a malicious website using a specially crafted Winamp skin to place and execute arbitrary programs. With Internet Explorer this can be done without user interaction.

An XML document in the Winamp skin zip file can reference a HTML document using the "browser" tag and get it to run in the "Local computer zone". This can be exploited to run an executable program embedded in the Winamp skin file using the "object" tag and the "codebase" attribute.

NOTE: The vulnerability is reportedly being exploited in the wild.

The vulnerability has been confirmed on a fully patched system with Winamp 5.04 using Internet Explorer 6.0 on Microsoft Windows XP SP1.

News source: Secunia security

Read full story...




This is a GrokNews Entry: (what is grok?)





Similar Items

Winamp has extremely critical vulnerability

Grok Headline matches for Winamp has extremely critical vulnerability

Re: 0day critical vulnerability/exploit
targets Winamp users in the wild


Re: 0day critical vulnerability/exploit
targets Winamp users in the wild
08/28/2004 02:56 PM
K-OTiK Security (Aug 28 2004)

0day critical vulnerability/exploit
targets Winamp users in the wild


0day critical vulnerability/exploit
targets Winamp users in the wild
08/27/2004 01:32 PM
K-OTiK Security (Aug 26 2004)

4 New "Extremely Critical" IE
Vulnerabilities


4 New "Extremely Critical" IE
Vulnerabilities
07/13/2004 11:55 AM

Apple Investigating "Extremely Critical"
Flaw


Apple Investigating "Extremely Critical"
Flaw
05/19/2004 01:31 AM
Apple says it is taking the Mac OS X security vulnerability "very seriously" and is "acitvely investigating this potential security issue." By MacNN (via MyAppleMenu)

Notes and Tips: "Extremely Critical"
Security Flaw


Notes and Tips: "Extremely Critical"
Security Flaw
05/18/2004 07:23 AM
A Secunia advisory rates the Mac OS X Help security problem "extremely critical".

Apple investigating "extremely critical"
flaw | MacNN News


Apple investigating "extremely critical"
flaw | MacNN News
05/19/2004 11:54 PM
Apple Investigating "Extremely Critical" Flaw

macnn.com/news/24753
track this site | 5 links


Fix for critical MacOS X vulnerability


Fix for critical MacOS X vulnerability 05/19/2004 02:47 AM
If you use an OS 10.3 Mac with Safari or MSIE, you absolutely must follow the instructions in this post to block a really serious attack that Apple hasn't patched (though they've reportedly known about this since February). Alternatively, you could always run Mozilla or one of its variants -- a free, open source browser in which vulnerabilities are corrected as soon as they're discovered (not when Apple decides to get around to it). Link (via Electrolite)

Another critical Windows vulnerability
found


Another critical Windows vulnerability
found
03/21/2003 01:36 PM
Another critical Windows vulnerability found

track this site | 3 links


Patch available for critical Veritas i3
Server vulnerability


Patch available for critical Veritas i3
Server vulnerability
04/13/2005 05:15 PM
Posted by NGSSoftware Insight Security Research, Apr 12 2005

[HAT-SQUAD] NetCat Remote Critical
Vulnerability, Poc included


[HAT-SQUAD] NetCat Remote Critical
Vulnerability, Poc included
12/28/2004 03:27 PM
Hat-Squad Security Team (Dec 27 2004)

Re: [HAT-SQUAD] NetCat Remote Critical
Vulnerability, Poc included


Re: [HAT-SQUAD] NetCat Remote Critical
Vulnerability, Poc included
12/28/2004 07:20 PM
Chris Wysopal (Dec 28 2004)

Microsoft warns of critical
vulnerability in JPEG images


Microsoft warns of critical
vulnerability in JPEG images
09/15/2004 06:14 AM
PC Pro Sep 15 2004 10:37AM GMT

Finjan Software Discovers a New Critical
Vulnerability In Yahoo E-mail Service


Finjan Software Discovers a New Critical
Vulnerability In Yahoo E-mail Service
12/11/2003 01:18 PM
Dror Shalev (Dec 10 2003)

Critical Path in critical condition


Critical Path in critical condition 12/25/2003 09:17 AM
CNET Dec 25 2003 9:16AM ET

Tim Lambert has done the extremely
useful exercise


Tim Lambert has done the extremely
useful exercise
11/06/2003 04:05 AM
Surf here to join the fun .. Tim Lambert's visual chart

cgi.cse.unsw.edu.au/~lambert/cgi-bin/blog/surveys/compass.html
track this site | 6 links


Extremely Bitter Divorce Dot Com


Extremely Bitter Divorce Dot Com 03/13/2003 10:22 AM
How rough was Kevin and Erika's divorce? Perhaps this will give you an idea: "The Webmaster regrets that he can no longer post sexually explicit pictures of Captain amErika performing sodomy on this website." (03-09)

Memphis is extremely cool


Memphis is extremely cool 03/14/2005 05:51 PM
On my way back from Memphis, where I spoke at the Rhodes College Institute on the Profession of the Law. This is an annual event (well, my speaking there is not an annual event, but you understand), and I was struck not just by the College (which seems plucked from Oxbridge), but by the seriousness with which 100 lawyers spend a morning thinking, and arguing, about real issues. Maybe its something about the pure Tennessee air (my mom's from Chattanooga), or the distance from Washington, DC. But it is such a pleasure to be able to talk about these issues with people thinking about them genuinely.

Welcome Our Extremely Junior Editor


Welcome Our Extremely Junior Editor 08/23/2004 12:23 PM
Join with me in welcoming Wi-Fi Networking News's latest addition, Ben Fleishman: Our extremely junior editor joined the staff at 12.26 a.m. on Wed., Aug. 18, and immediately set to work reporting on wireless anti-theft baby tags, and hospital allegations that cellular telephones interfere with certain medical telemetry. Ben will focus generally on the home front, studying wireless baby monitors, home networking, and D2D (diaper-to-diaper) information interchange. While I'm at work training our new cub reporter round the clock, senior editor Nancy Gohring will be handling our site's regular reporting....

Fast Take: How to Work Extremely Well


Fast Take: How to Work Extremely Well 04/11/2005 06:11 AM
Tips from the trenches.

xsdb -- eXtremely Simple DataBase


xsdb -- eXtremely Simple DataBase 12/09/2003 02:33 PM
xsdb goes alpha

" Extremely funny Bush parodies"


" Extremely funny Bush parodies" 08/01/2004 03:22 AM

The thing I like most about Macs is it's
extremely sharp and


The thing I like most about Macs is it's
extremely sharp and
09/23/2004 11:22 PM
TechTree Sep 24 2004 3:34AM GMT

An extremely beautiful Free Culture
eBook


An extremely beautiful Free Culture
eBook
04/09/2004 04:06 PM
There is an extremely beautiful ebook version of Free Culture here. I continue to be astonished at the creativity free culture (the idea, not the book) inspires.

Extremely mediocore review, Mr Punit
Lo.... whatever made yo


Extremely mediocore review, Mr Punit
Lo.... whatever made yo
08/22/2004 06:16 AM
TechTree Aug 22 2004 8:43AM GMT

Extremely Cool Collection of 78s At
Internet Archive


Extremely Cool Collection of 78s At
Internet Archive
06/05/2005 11:21 PM
I don't know why I haven't mentioned this cool collection of 78s at the Internet Archive before. They're available at http://www.archive.org/audio/audiolisting-browseartists.php?collection =78rpm . The page I'm pointing to leads to a...

The Webl0g: An Extremely Democratic Form
in Journalism


The Webl0g: An Extremely Democratic Form
in Journalism
03/08/2004 11:19 PM
In this chapter for Extreme Democracy: The Book, a collection taking shape now, I revisit my list, "ten things radical about the weblog form in journalism." (PressThink's most popular post.)

USNews.com: Shining a light in an
extremely dark corner (7/19/04)


USNews.com: Shining a light in an
extremely dark corner (7/19/04)
07/13/2004 03:18 AM
New Uncensored Parts of Taguba Report .. the annexes

usnews.com/usnews/issue/040719/usnews/19prison.b.htm
track this site | 4 links


"potential terrorists possessing
extremely dangerous chemical..."


"potential terrorists possessing
extremely dangerous chemical..."
12/07/2003 03:41 AM

Intel Pentium 4 Extremely Expensive
Edition to ship Monday


Intel Pentium 4 Extremely Expensive
Edition to ship Monday
10/31/2003 04:57 AM
Systems too

Intel Pentium 4 Extremely Expensive
Edition To Ship Monday


Intel Pentium 4 Extremely Expensive
Edition To Ship Monday
10/31/2003 10:38 AM

extremely graphic pictures of American
soldiers torturing Iraqi prisoners


extremely graphic pictures of American
soldiers torturing Iraqi prisoners
05/01/2004 02:10 AM
Photos of Iraqis Being Abused by US Personnel .. these graphic and disturbing screen captures .. The Memory Hole .. supplements

thememoryhole.org/war/iraqis_tortured
track this site | 5 links


Winamp 5.01 is out!


Winamp 5.01 is out! 12/20/2003 06:17 AM

Winamp 5 RC2


Winamp 5 RC2 11/19/2003 08:10 PM

WinAmp 5.03c


WinAmp 5.03c 06/25/2004 10:07 AM

Winamp 5.05


Winamp 5.05 08/28/2004 10:02 AM

"Winamp"


"Winamp" 12/17/2003 09:35 AM

Winamp 2 + Winamp 3 = Winamp 5!


Winamp 2 + Winamp 3 = Winamp 5! 12/16/2003 10:04 AM
An anonymous coward writes: Having been a loyal iTunes user for quite some time, after seeing the report on Ars Technica about the newly released Winamp 5 ...

Winamp 5.04


Winamp 5.04 07/28/2004 04:05 AM

Winamp: 2+3=5


Winamp: 2+3=5 12/15/2003 11:41 PM
Winamp 5.0 Final has been unleashed! So how does Winamp 5 compare to Winamp 2 and 3? This author has only had a few minutes to play around with it, but it looks like the perfect combination of the two.
Grok Description matches for Winamp has extremely critical vulnerability
GrokA matches for Winamp has extremely critical vulnerability

JavaScript Popup Media Player


JavaScript Popup Media Player 09/23/2004 10:43 AM
Playing videos in popup windows is often a simple task, but when you end up with multiple pages for each individual video, things can quickly become complicated. We can clean that up with JavaScript, and still make it accessible to users who don't have JavaScript. By Jonathan Fenocchi. 0923

How to Create Universally Related Popup
Menus with Javascript: Single Form
Version III


How to Create Universally Related Popup
Menus with Javascript: Single Form
Version III
06/17/2005 03:32 PM
In this article, the author modifies Andy King's original version of the Universally Related Popup Menus (URPMs). His intention was to make it more suitable for submitting data to a server and to simplify the JavaScript "O" objects used to store all the related list data. Read on to see how he did it. By Rob Gravelle. 0613

Firefox Tests Beefed-up Popup Blocker


Firefox Tests Beefed-up Popup Blocker 04/02/2005 02:53 AM
Finally! Firefox is working with a new patch that will make short work of those annoying Flash based pop-up ads we have all come to loathe. It is my hope that this will provide us with some relief for a little longer than the original blocker….

Direct and Related Links for 'Firefox Tests Beefed-up Popup Blocker'


Startup Looks To Build Business Around
Firefox (TechWeb)


Startup Looks To Build Business Around
Firefox (TechWeb)
04/13/2005 04:21 AM
TechWeb - Startup Round Two announces plans to build software and services that make the Firefox browser consumers' control panel for all web activity.

Firefox JavaScript security problem!


Firefox JavaScript security problem! 04/05/2005 05:22 PM
TechSpot Apr 5 2005 9:44PM GMT

Firefox Patch on the Way for JavaScript
Engine Flaw


Firefox Patch on the Way for JavaScript
Engine Flaw
04/08/2005 08:17 PM
The Mozilla Foundation plans to ship Firefox 1.0.3 as early as this weekend to correct an information disclosure vulnerability.

Firefox JavaScript Engine Flaw Flagged


Firefox JavaScript Engine Flaw Flagged 04/04/2005 11:57 PM
The vulnerability carries a "moderately critical" rating and could lead to the disclosure of sensitive information.

Firefox Patch on the Way for JavaScript
Engine Flaw (Ziff Davis)


Firefox Patch on the Way for JavaScript
Engine Flaw (Ziff Davis)
04/08/2005 08:35 PM
Ziff Davis - The Mozilla Foundation plans to ship Firefox 1.0.3 as early as this weekend to correct an information disclosure vulnerability.

Mozilla Firefox JavaScript Engine
Information Disclosure Vulnerability


Mozilla Firefox JavaScript Engine
Information Disclosure Vulnerability
04/05/2005 01:58 AM
Secunia Advisory: SA14820 Critical: Moderately critical Impact: Exposure of system information, Exposure of sensitive information Where: From remote Solution Status: Unpatched Software: Mozilla Firefox 0.x, Mozilla Firefox 1.x A vulnerability has been discovered in Mozilla Firefox, which can be exploited by malicious people to gain knowledge of potentially sensitive information. The vulnerability is caused due to an error in the JavaScript engine, as a “lambda” replace exposes arbitrary amounts of heap memory after the end…

D irect and Related Links for 'Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability'


4096 Color Wheel


4096 Color Wheel 12/16/2003 07:49 AM
four thousand and ninety six colors .. 4096 color wheel

ficml.org/jemimap/style/color/wheel.html
track this site | 5 links


Professional JavaScript for Web
Developers: JavaScript in the Browser,
Pt. 1


Professional JavaScript for Web
Developers: JavaScript in the Browser,
Pt. 1
06/22/2005 02:51 AM
Web browsers have come a long way over the years and can now handle a variety of file formats, not just conventional HTML. Here, you'll learn how JavaScript fits into HTML, other languages, and some basic concepts of the Browser Object Model (BOM). By WROX Press. 0620

Tech Bytes


Tech Bytes 07/28/2004 01:05 AM
Computerworld Singapore Jul 28 2004 5:49AM GMT

Bytes From a Banner


Bytes From a Banner 12/02/2003 02:01 AM
Radically scaling bandwidth and interface refactoring make strange bedfellows. For example, one interesting design problem that's presented when dealing with critically accessed pages (i.e. Google's search results page) is tradeoff. Meaning: An interface feature that could add weight to the...

Apple Bytes: The Mac At 20


Apple Bytes: The Mac At 20 01/23/2004 02:23 PM
Memorable beginning, lasting influence. By MNico Macdonald (Silicon.com via MyAppleMenu)

Bits and Bytes for May 28, 2004


Bits and Bytes for May 28, 2004 05/28/2004 06:27 PM
InternetNews.com-1 hour ago ... These include anti-spam company Brightmail, comparison-shopping engine Shopping.com and Google, giving rise to speculation about a possible bubble such as that ...

Steve's Apple Bytes


Steve's Apple Bytes 02/01/2005 09:13 PM
My older, wiser brother Steve has a smart take on Apple's Macworld Expo announcements, even though I'm still right (ahem) about the "trade secrets" question...


Cyber front has favorable bytes


Cyber front has favorable bytes 08/23/2004 10:57 AM

Re: [Full-Disclosure] Crash IE with 11
bytes ;)


Re: [Full-Disclosure] Crash IE with 11
bytes ;)
07/28/2004 11:49 PM
Berend-Jan Wever (Jul 28 2004)

BCS member swaps bytes for Basra


BCS member swaps bytes for Basra 06/22/2004 10:44 AM
Computer Weekly Jun 22 2004 2:13PM GMT

IAR Bits and Bytes for November 6, 2003


IAR Bits and Bytes for November 6, 2003 11/06/2003 10:47 PM
Internet News Nov 6 2003 9:06PM ET

SCI-BYTES - What's New in Research -
Year 2003


SCI-BYTES - What's New in Research -
Year 2003
10/29/2003 11:22 AM
SCI-BYTES - What's New in Research - Year 2003
http://in-cites.co m/research/2003/index.html

ISI®, as a publisher of Web-based information resources, recognizes the need for and value of reliable high-quality information to individual researchers and users as well as to the larger library community. Whether tracking the progress of on-going research or exploring new topics, ISI recognizes that you need to be kept current and aware of what's changing in your intellectual community as well as in the various disciplines that you serve.

What's really hot in research? Each week, the ISI Research Services Group provides an update based on their Research Performance & Evaluation Tools. Note: SCI-BYTES is a feature within incites - an editorial component of ISI Essential Science Indicators Web product.

IAR Bits and Bytes for October 31, 2003


IAR Bits and Bytes for October 31, 2003 10/31/2003 11:49 PM
Internet News Oct 31 2003 10:17PM ET

IAR Bits and Bytes for December 9, 2003


IAR Bits and Bytes for December 9, 2003 12/09/2003 03:44 PM
Internet News Dec 9 2003 2:22PM ET

How many bytes to store all human
speech, ever?


How many bytes to store all human
speech, ever?
01/02/2004 06:10 PM
Interesting discussion of the number of bytes necessary to store all the syllables ever uttered by every person who ever lived, and when acquiring that number of bytes will be in the realm of affordability.
First, the proposed configuration would amount to 1.2 petabytes, which is a thousand times smaller than 1.2 exabytes. Second, a 5 exabyte store would roughly be eight thousand times too small to store "all words ever spoken by human beings", at least in audio form. Therefore the 2007 cluster's storage would be too small by a factor of about 32 million rather than a factor of 4. I freely confess that maybe the authors were thinking about text -- but in the first place I'm a phonetician, and in the second place most human languages have not had a written form. So bear with me here for a while.
Link (via Ben Hammersley)

Counter of C/C++ source lines and bytes


Counter of C/C++ source lines and bytes 05/28/2004 11:05 AM
Counter of C/C++ source lines and bytes : Release 1.3.1

Tech bits, Science bytes


Tech bits, Science bytes 12/30/2003 07:45 PM
Straits Times Dec 30 2003 7:12PM ET

Bits & Bytes for January 26, 2004


Bits & Bytes for January 26, 2004 01/26/2004 08:43 PM
Internet News Jan 27 2004 0:35AM GMT

Popup Killer v4.0


Popup Killer v4.0 06/19/2004 07:21 AM
PopUp Killer is a small program that can automatically close previously selected Windows. [Shareware $13.00 30 Days 3.4 MB]

Popup Silencer II v1.0


Popup Silencer II v1.0 09/26/2004 10:53 AM
Popup Silencer II is a software to make your Internet browsing faster by blocking popups and popThe situation is well known: you try to open a webpage and 5 more pages open at the same time. This makes you Internet speed 5 times slower. Popup Silencer II is a utility to make your Web browsing more enjoyable by eliminating the distracting popups. [Shareware $24.00 5 Days 647 KB]

Zero PopUp Killer XP v5.2


Zero PopUp Killer XP v5.2 12/09/2003 08:42 PM
Zero Popup Killer XP is a small, effective, and intelligent anti-pop-up software product that can kill annoying pop-up windows without human intervention by using artificial intelligence and intelligent agent technologies. It is light on your system's resources and resides in the system tray. It works as an add-in for Internet Explorer and automatically starts when you start up the IE browser. [Shareware $12.00 1.64 MB]

Winamp has extremely critical vulnerability

The following phrases have been identified by the grok system as matching this entry: firefox javascript xml "4096 bytes" notebook popup at startup [.shellclassinfo]

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

New holographic
discs look like a
DVD but hold a
terabyte

August 25, 2004
Developing an
Effective Data
Protection Strategy

Building a Diskless
2.6 Firewall

Vim Macros for
Editing DocBook
Documents

Linux in Government:
Technical Aspects of
the Emergency
Response Network
System

If There's a
Wireless Signal in
the Woods but No One
Around to Use It,
Can It Still Be
Stolen?

WiFi Advice
RSS Screen Saver for
Libraries!

Another Forced
Hiatus

HP to tempt holiday
shoppers with sights
and sounds

HP cues iPod
Ex-Palm CEO
Yankowski to head
Majesco

Washingtonian
Mariachi in the
Morning

HP's Digital Desires
Little Debbie Lives!
FC Now: News You
Can't Use

FC Now: Trump and
Circumstance

FC Now: The More,
the Better?

New Mozilla.org
Design

New Photo Collection
from the Bureau of
Land Management

Genealogy and RSS
Fagan Finder
Launches URL
Information Tool

Search A Local Index
of Pages With Recall
Toolbar

TSLAC Creates
Searchable Database

Wifi/Video iPod?
HP iPod To Appear
September 5?
[Updated x3]

Is your webcam
watching you when
you didnt turn it on

Advice on Moving
Feedback and e-mail
replies

MIcrosoft to open
it's own music store
and challenge iTunes

One disk to Mediums
CD on one side DVD
on other

MPAA sues DVD chip
manufacture which
apparently allowed
Fair Use Recordiongs

Intel Slashes Chip
Prices

Justice Department
goes after P2P
Network

A New MP3 Weblog
Doc Searls ponies up
some nice Pictures

Spoofing XP SP2
Security Center

Science being
advanced by linking
150,000 home
computers

The Corporate Weblog
Manifesto by Robert
Scoble

RSS "Show us the
Money"

Being Pitched by
Technology Companies

Google Results via
RSS

My RSS reader saves
me about 300 hours a
week

Blogger turns five
The Google Browser
ANN: TopStyle Pro
3.11 BETA 3

US Dept of Education
supports RSS

Internet Explorer
Blog

what is grok?