Gentoo Archives: gentoo-announce

From: Stefan Cornelius <dercorny@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200607-11 ] TunePimp: Buffer overflow
Date: Fri, 28 Jul 2006 20:19:34
Message-Id: 44CA6BDF.4030204@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200607-11
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: TunePimp: Buffer overflow
9 Date: July 28, 2006
10 Bugs: #140184
11 ID: 200607-11
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in TunePimp has been reported which could lead to the
19 execution of arbitrary code.
20
21 Background
22 ==========
23
24 The TunePimp library (also referred to as libtunepimp) is a development
25 library geared towards developers who wish to create MusicBrainz
26 enabled tagging applications.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 media-libs/tunepimp <= 0.4.2 Vulnerable!
35 -------------------------------------------------------------------
36 NOTE: Certain packages are still vulnerable. Users should migrate
37 to another package if one is available or wait for the
38 existing packages to be marked stable by their
39 architecture maintainers.
40
41 Description
42 ===========
43
44 Kevin Kofler has reported a vulnerability where three stack variables
45 are allocated with 255, 255 and 100 bytes respectively, yet 256 bytes
46 are read into each. This could lead to buffer overflows.
47
48 Impact
49 ======
50
51 Running an affected version of TunePimp could lead to the execution of
52 arbitrary code by a remote attacker.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 TunePimp has been masked in Portage pending the resolution of these
63 issues. TunePimp users are advised to uninstall the package until
64 further notice:
65
66 # emerge --ask --unmerge "media-libs/tunepimp"
67
68 References
69 ==========
70
71 [ 1 ] CVE-2006-3600
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3600
73 [ 2 ] MusicBrainz bug #1764
74 http://bugs.musicbrainz.org/ticket/1764
75
76 Availability
77 ============
78
79 This GLSA and any updates to it are available for viewing at
80 the Gentoo Security Website:
81
82 http://security.gentoo.org/glsa/glsa-200607-11.xml
83
84 Concerns?
85 =========
86
87 Security is a primary focus of Gentoo Linux and ensuring the
88 confidentiality and security of our users machines is of utmost
89 importance to us. Any security concerns should be addressed to
90 security@g.o or alternatively, you may file a bug at
91 http://bugs.gentoo.org.
92
93 License
94 =======
95
96 Copyright 2006 Gentoo Foundation, Inc; referenced text
97 belongs to its owner(s).
98
99 The contents of this document are licensed under the
100 Creative Commons - Attribution / Share Alike license.
101
102 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature