• On The Insider: Bruno Film Edited Due to Jackson's Death
January 11, 2008 9:55 AM PST

AOL Radio re-posts security update

by Dawn Kawamoto

AOL Radio may need to turn up the volume to get its users to download the latest security update, or its listeners may tune them out.

AOL Radio re-posted its Unagi plug-in 2.6.2.6 on Friday, but it failed to stress that users running versions of AOL Radio prior to August could be facing a security risk if they didn't download the update.

It turns out that AOL Radio users running version 2.6.1.11 are at risk, said Thomas Chau, who runs the AOL Radio blog. He noted, however, that anyone who downloaded the Unagi plug-in 2.6.2.6 originally posted on the site last fall, or is running the recently released AOL Radio 4.0 beta are safe.

The earlier AOL Radio version contains a security flaw that could allow attackers to compromise users' computers, after viewing a malicious Web site, document, or HTML e-mail, according to a report by the U.S. Computer Emergency Readiness Team (US-CERT) that was released earlier this week.

The security flaw is found in an application, AOLMediaPlaybackControl.exe, that is used by AOL Radio to stream audio in Web pages. But the application contains a stack buffer overflow, according to US-CERT, which could be exploited via the ActiveX control used with the application.

Dawn Kawamoto covers enterprise security and financial news relating to technology for CNET News. E-mail Dawn.
advertisement
Click here!
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right