Gentoo Archives: gentoo-announce

From: Matthias Geerdsen <vorlon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200504-19 ] MPlayer: Two heap overflow vulnerabilities
Date: Wed, 20 Apr 2005 07:28:28
Message-Id: 20050420072827.GA29678@kosh.atw.wh.local
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200504-19
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: MPlayer: Two heap overflow vulnerabilities
9 Date: April 20, 2005
10 Bugs: #89277
11 ID: 200504-19
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Two vulnerabilities have been found in MPlayer which could lead to the
19 remote execution of arbitrary code.
20
21 Background
22 ==========
23
24 MPlayer is a media player capable of handling multiple multimedia file
25 formats.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-video/mplayer < 1.0_pre6-r4 >= 1.0_pre6-r4
34
35 Description
36 ===========
37
38 Heap overflows have been found in the code handling RealMedia RTSP and
39 Microsoft Media Services streams over TCP (MMST).
40
41 Impact
42 ======
43
44 By setting up a malicious server and enticing a user to use its
45 streaming data, a remote attacker could possibly execute arbitrary code
46 on the client computer with the permissions of the user running
47 MPlayer.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All MPlayer users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0_pre6-r4"
61
62 References
63 ==========
64
65 [ 1 ] MPlayer News: Real RTSP heap overflow
66 http://www.mplayerhq.hu/homepage/design7/news.html#vuln10
67 [ 2 ] MPlayer News: MMST heap overflow
68 http://www.mplayerhq.hu/homepage/design7/news.html#vuln11
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200504-19.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2005 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.0