R E L A T E D   C O N T E N T
ADVERTISEMENT

MP3 users warned about security threat

Internet users downloading MP3 music files have been warned about a security hole in a popular MP3 player that could let a hacker execute harmful code on their system.

Jo Ticehurst, vnunet.com 12 Jan 2000
ADVERTISEMENT

Internet users downloading MP3 music files have been warned about a security hole in a popular MP3 player that could let a hacker execute harmful code on their system.

According to security company Panda Software, the vulnerability in the Nullsoft Winamp 2.10 player consists of a stack overflow error that can be produced through the use of PLS extension files.

These files are used by Winamp to store playlists and are often exchanged among Internet Relay Chat (IRC) users so that they can check out tracks before receiving an MP3 file.

The overflow is produced by including more than 580 bytes after the 'FileN=' tag, which makes it possible to include more code that will be run on the user's system when the malformed PLS file is opened. This code may include any kind of destructive action.

Panda said it considered the security hole to be "serious" and that Winamp is currently one of the most widely used audio players available for Windows 95, 98 and NT platforms.

The company recommended users not to open PLS files that come in from unknown sources and to upgrade their players to the latest available version, which is currently 2.50.

Neil Barrett, technical director at security company Information Risk Management, commented: "A large percentage of security holes that have been discovered in the last decade have been buffer overflow, which is what this is. Arbitrary code is dangerous as commands execute as if they are the user."

He added; "We always tell users not to open attachments if they come from somewhere they don't recognise. The problem with MP3 is that it's not always easy to work out where it's from, and given how easy it is to spoof email you have to be doubly careful."

Nullsoft failed to respond to vnunet.com's requests for comment.

See also:

The music industry has been shaken up by the emergence of MP3-based music websites such as Napster. Critics accuse them of facilitating piracy while advocates say they make it easier for unsigned musicians to have their music heard. We look at what all the fuss is about.  08 Aug 2000
Ford and Delta Airlines' plans to offer employees super-cheap PCs in a bid to create a 'wired workplace' has been met with concern from both security experts and IT managers.  09 Feb 2000
I2Go has come up with an MP3 player that lets you listen to your email and record responses as MP3 files.  10 Jan 2000
Microsoft has given in to consumer pressure by announcing support for the popular, if controversial, MP3 music compression format in its audio player software for mobile devices.  06 Jan 2000
Consumer electronics heavyweight Philips has joined the MP3 foray with a player dubbed 'Rush'.  18 Nov 1999

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities