Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200705-21 ] MPlayer: Two buffer overflows
Date: Wed, 30 May 2007 18:44:21
Message-Id: 20070530181829.GE29402@falco.falcal.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200705-21
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: MPlayer: Two buffer overflows
9 Date: May 30, 2007
10 Bugs: #168917
11 ID: 200705-21
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Two vulnerabilities have been discovered in MPlayer, each one could
19 lead to the execution of arbitrary code.
20
21 Background
22 ==========
23
24 MPlayer is a media player incuding support for a wide range of audio
25 and video formats.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-video/mplayer < 1.0.20070321 >= 1.0.20070321
34
35 Description
36 ===========
37
38 A buffer overflow has been reported in the DMO_VideoDecoder_Open()
39 function in file loader/dmo/DMO_VideoDecoder.c. Another buffer overflow
40 has been reported in the DS_VideoDecoder_Open() function in file
41 loader/dshow/DS_VideoDecoder.c.
42
43 Impact
44 ======
45
46 A remote attacker could entice a user to open a specially crafted video
47 file, potentially resulting in the execution of arbitrary code with the
48 privileges of the user running MPlayer.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All MPlayer users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0.20070321"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2007-1246
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1246
68 [ 2 ] CVE-2007-1387
69 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1387
70 [ 3 ] GLSA 200704-09
71 http://www.gentoo.org/security/en/glsa/glsa-200704-09.xml
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 http://security.gentoo.org/glsa/glsa-200705-21.xml
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 http://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2007 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 http://creativecommons.org/licenses/by-sa/2.5