R E L A T E D   C O N T E N T
ADVERTISEMENT

MP3 users warned about security threat

Internet users downloading MP3 music files have been warned about a security hole in a popular MP3 player that could let a hacker execute harmful code on their system.

Jo Ticehurst, vnunet.com 12 Jan 2000
ADVERTISEMENT

Internet users downloading MP3 music files have been warned about a security hole in a popular MP3 player that could let a hacker execute harmful code on their system.

According to security company Panda Software, the vulnerability in the Nullsoft Winamp 2.10 player consists of a stack overflow error that can be produced through the use of PLS extension files.

These files are used by Winamp to store playlists and are often exchanged among Internet Relay Chat (IRC) users so that they can check out tracks before receiving an MP3 file.

The overflow is produced by including more than 580 bytes after the 'FileN=' tag, which makes it possible to include more code that will be run on the user's system when the malformed PLS file is opened. This code may include any kind of destructive action.

Panda said it considered the security hole to be "serious" and that Winamp is currently one of the most widely used audio players available for Windows 95, 98 and NT platforms.

The company recommended users not to open PLS files that come in from unknown sources and to upgrade their players to the latest available version, which is currently 2.50.

Neil Barrett, technical director at security company Information Risk Management, commented: "A large percentage of security holes that have been discovered in the last decade have been buffer overflow, which is what this is. Arbitrary code is dangerous as commands execute as if they are the user."

He added; "We always tell users not to open attachments if they come from somewhere they don't recognise. The problem with MP3 is that it's not always easy to work out where it's from, and given how easy it is to spoof email you have to be doubly careful."

Nullsoft failed to respond to vnunet.com's requests for comment.

See also:

The music industry has been shaken up by the emergence of MP3-based music websites such as Napster. Critics accuse them of facilitating piracy while advocates say they make it easier for unsigned musicians to have their music heard. We look at what all the fuss is about.  08 Aug 2000
Ford and Delta Airlines' plans to offer employees super-cheap PCs in a bid to create a 'wired workplace' has been met with concern from both security experts and IT managers.  09 Feb 2000
I2Go has come up with an MP3 player that lets you listen to your email and record responses as MP3 files.  10 Jan 2000
Microsoft has given in to consumer pressure by announcing support for the popular, if controversial, MP3 music compression format in its audio player software for mobile devices.  06 Jan 2000
Consumer electronics heavyweight Philips has joined the MP3 foray with a player dubbed 'Rush'.  18 Nov 1999

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities