Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200608-24 ] AlsaPlayer: Multiple buffer overflows
Date: Sat, 26 Aug 2006 12:26:17
Message-Id: 200608261412.07954@msgid.falco.bz
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200608-24
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: AlsaPlayer: Multiple buffer overflows
9 Date: August 26, 2006
10 Bugs: #143402
11 ID: 200608-24
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 AlsaPlayer is vulnerable to multiple buffer overflows which could lead
19 to the execution of arbitrary code.
20
21 Background
22 ==========
23
24 AlsaPlayer is a heavily multithreaded PCM player that tries to utilize
25 ALSA utilities and drivers. As of June 2004, the project is inactive.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-sound/alsaplayer <= 0.99.76-r3 Vulnerable!
34 -------------------------------------------------------------------
35 NOTE: Certain packages are still vulnerable. Users should migrate
36 to another package if one is available or wait for the
37 existing packages to be marked stable by their
38 architecture maintainers.
39
40 Description
41 ===========
42
43 AlsaPlayer contains three buffer overflows: in the function that
44 handles the HTTP connections, the GTK interface, and the CDDB querying
45 mechanism.
46
47 Impact
48 ======
49
50 An attacker could exploit the first vulnerability by enticing a user to
51 load a malicious URL resulting in the execution of arbitrary code with
52 the permissions of the user running AlsaPlayer.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 AlsaPlayer has been masked in Portage pending the resolution of these
63 issues. AlsaPlayer users are advised to uninstall the package until
64 further notice:
65
66 # emerge --ask --unmerge "media-sound/alsaplayer"
67
68 References
69 ==========
70
71 [ 1 ] CVE-2006-4089
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-4089
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-200608-24.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 http://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2006 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/2.5cheers