Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200803-16 ] MPlayer: Multiple buffer overflows
Date: Mon, 10 Mar 2008 20:50:23
Message-Id: 47D5AC3A.4050806@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200803-16
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: MPlayer: Multiple buffer overflows
12 Date: March 10, 2008
13 Bugs: #208566
14 ID: 200803-16
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities have been discovered in MPlayer, possibly
22 allowing for the remote execution of arbitrary code.
23
24 Background
25 ==========
26
27 MPlayer is a media player incuding support for a wide range of audio
28 and video formats.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 media-video/mplayer < 1.0_rc2_p25993 >= 1.0_rc2_p25993
37
38 Description
39 ===========
40
41 The following errors have been discovered in MPlayer:
42
43 * Felipe Manzano and Anibal Sacco (Core Security Technologies)
44 reported an array indexing error in the file libmpdemux/demux_mov.c
45 when parsing MOV file headers (CVE-2008-0485).
46
47 * Damian Frizza and Alfredo Ortega (Core Security Technologies)
48 reported a boundary error in the file libmpdemux/demux_audio.c when
49 parsing FLAC comments (CVE-2008-0486).
50
51 * Adam Bozanich (Mu Security) reported boundary errors in the
52 cddb_parse_matches_list() and cddb_query_parse() functions in the
53 file stream_cddb.c when parsing CDDB album titles (CVE-2008-0629) and
54 in the url_scape_string() function in the file stream/url.c when
55 parsing URLS (CVE-2008-0630).
56
57 Impact
58 ======
59
60 A remote attacker could entice a user to open a specially crafted file,
61 possibly resulting in the execution of arbitrary code with the
62 privileges of the user running MPlayer.
63
64 Workaround
65 ==========
66
67 There is no known workaround at this time.
68
69 Resolution
70 ==========
71
72 All MPlayer users should upgrade to the latest version:
73
74 # emerge --sync
75 # emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0_rc2_p25993"
76
77 References
78 ==========
79
80 [ 1 ] CVE-2008-0485
81 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0485
82 [ 2 ] CVE-2008-0486
83 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0486
84 [ 3 ] CVE-2008-0629
85 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0629
86 [ 4 ] CVE-2008-0630
87 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0630
88
89 Availability
90 ============
91
92 This GLSA and any updates to it are available for viewing at
93 the Gentoo Security Website:
94
95 http://security.gentoo.org/glsa/glsa-200803-16.xml
96
97 Concerns?
98 =========
99
100 Security is a primary focus of Gentoo Linux and ensuring the
101 confidentiality and security of our users machines is of utmost
102 importance to us. Any security concerns should be addressed to
103 security@g.o or alternatively, you may file a bug at
104 http://bugs.gentoo.org.
105
106 License
107 =======
108
109 Copyright 2008 Gentoo Foundation, Inc; referenced text
110 belongs to its owner(s).
111
112 The contents of this document are licensed under the
113 Creative Commons - Attribution / Share Alike license.
114
115 http://creativecommons.org/licenses/by-sa/2.5
116 -----BEGIN PGP SIGNATURE-----
117 Version: GnuPG v2.0.7 (GNU/Linux)
118 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
119
120 iD8DBQFH1aw6uhJ+ozIKI5gRAlmEAJ4ygxVXlGiWqBzdc5KMUEbF0omH9gCgibFB
121 QBUdO9db/Z4Zm2aqaiznRAI=
122 =JZmi
123 -----END PGP SIGNATURE-----
124 --
125 gentoo-announce@l.g.o mailing list