Gentoo Archives: gentoo-announce

From: Tobias Heinlein <keytoaster@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200805-22 ] MPlayer: User-assisted execution of arbitrary code
Date: Thu, 29 May 2008 14:36:04
Message-Id: 483EBE19.2050502@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200805-22
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: MPlayer: User-assisted execution of arbitrary code
9 Date: May 29, 2008
10 Bugs: #215006
11 ID: 200805-22
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 An integer overflow vulnerability in MPlayer may allow for the
19 execution of arbitrary code.
20
21 Background
22 ==========
23
24 MPlayer is a media player including support for a wide range of audio
25 and video formats.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-video/mplayer < 1.0_rc2_p26753 >= 1.0_rc2_p26753
34
35 Description
36 ===========
37
38 k`sOSe reported an integer overflow vulnerability in the
39 sdpplin_parse() function in the file stream/realrtsp/sdpplin.c, which
40 can be exploited to overwrite arbitrary memory regions via an overly
41 large "StreamCount" SDP parameter.
42
43 Impact
44 ======
45
46 A remote attacker could entice a user to open a specially crafted media
47 file, possibly resulting in the execution of arbitrary code with the
48 privileges of the user running MPlayer.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All MPlayer users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose
62 ">=media-video/mplayer-1.0_rc2_p26753"
63
64 References
65 ==========
66
67 [ 1 ] CVE-2008-1558
68 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1558
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200805-22.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2008 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature