GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon May 01, 2006 3:26 pm Post subject: [ GLSA 200605-01 ] MPlayer: Heap-based buffer overflow |
|
|
Gentoo Linux Security Advisory
Title: MPlayer: Heap-based buffer overflow (GLSA 200605-01)
Severity: normal
Exploitable: remote
Date: May 01, 2006
Updated: June 21, 2006
Bug(s): #127969
ID: 200605-01
Synopsis
MPlayer contains multiple integer overflows that may lead to a heap-based buffer overflow.
Background
MPlayer is a media player that supports many multimedia file types.
Affected Packages
Package: media-video/mplayer
Vulnerable: < 1.0.20060415
Unaffected: >= 1.0.20060415
Unaffected: >= 1.0_pre8
Architectures: All supported architectures
Package: media-video/mplayer-bin
Vulnerable: < 1.0.20060415
Unaffected: >= 1.0.20060415
Unaffected: >= 1.0_pre8
Architectures: All supported architectures
Description
Xfocus Team discovered multiple integer overflows that may lead to a heap-based buffer overflow.
Impact
An attacker could entice a user to play a specially crafted multimedia file, potentially resulting in the execution of arbitrary code with the privileges of the user running the application.
Workaround
There is no known workaround at this time.
Resolution
All MPlayer users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0.20060415" | All MPlayer binary users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/mplayer-bin-1.0.20060415" |
References
CVE-2006-1502
Last edited by GLSA on Fri Jun 23, 2006 4:17 am; edited 2 times in total |
|