First published: Fri Aug 01 2008(Updated: )
Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | <5.24 | |
Winamp | <5.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3441 has a severity rating of moderate due to its potential for arbitrary code execution via malicious updates.
To fix CVE-2008-3441, update Winamp to version 5.24 or later to ensure proper verification of updates.
With CVE-2008-3441, attackers can execute arbitrary code through man-in-the-middle attacks by exploiting unverified updates.
CVE-2008-3441 affects all versions of Winamp prior to 5.24.
Yes, using an outdated version of Winamp puts your system at risk for exploitation via CVE-2008-3441.