norrisa
Member
|
# Posted: 5 Feb 2006 09:00
Reply
The flaw was disclosed on Monday, when Winamp maker Nullsoft, a division of America Online, released an update to fix it. The company posted version 5.13 of Winamp, while Secunia and other security companies issued alerts about the problem. Secunia rated the issue "extremely critical," its highest rating.
"Not following the recommendation from Nullsoft to upgrade to version 5.13 could result in the extremely nasty CWS Looking-For.Home Search Assistant infection as well as an installation of our good friend SpySheriff," Thomas wrote. Antivirus software is not yet detecting this exploit, he wrote.
Home Search Assistant might monitor a user's activity and send out confidential information to its creator, according to Sunbelt's threat database. SpySheriff will display a false warning that the computer is infected with spyware. It then tries to persuade the user to buy a SpySheriff product, according to Sunbelt.
The Winamp problem affects version 5.12 of the media player. Earlier versions may also be affected. On Friday, the malicious Web site referred to by Sunbelt, 008k.com, appeared to be offline. The site displayed a message: "Site is closed for abuses."
References: Link
|