MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities
BID:10245
Info
MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities
| Bugtraq ID: | 10245 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0433 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery of these issues is credited to Diego Biurrun, Roberto Togni and Miguel Freitas. |
| Vulnerable: |
xine xine-lib 1-rc3c xine xine-lib 1-rc3b xine xine-lib 1-rc3a xine xine-lib 1-rc2 xine xine-lib 1-beta9 xine xine-lib 1-beta8 xine xine-lib 1-beta7 xine xine-lib 1-beta6 xine xine-lib 1-beta5 xine xine-lib 1-beta4 xine xine-lib 1-beta3 xine xine-lib 1-beta2 xine xine-lib 1-beta11 xine xine-lib 1-beta10 xine xine-lib 1-beta1 MPlayer MPlayer 1.0 pre3try2 |
| Not Vulnerable: |
xine xine-lib 1-rc4 MPlayer MPlayer 1.0 pre4 |
Discussion
MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities
Multiple buffer overruns were reported in realrtsp code shared between MPlayer and xine-lib.
One of the reported vulnerabilities may be triggered by enticing a user to request an excessively long URI from an RTSP server. Such a URI could be embedded in a playlist or possibly linked to from within a web page (if one of the players is configured as a handler for RTSP URIs).
Two more issues were also reported that could be exploited by a malicious RTSP server. One of the issues is exposed during session negotiation and the other issue is exposed when the clients receive RDT (Real Data Transfer) packets from the server.
These issues may permit remote attackers to execute arbitrary code in the context of the client user.
It should be noted that these issues are not present if support for realrtsp has been disabled.
Multiple buffer overruns were reported in realrtsp code shared between MPlayer and xine-lib.
One of the reported vulnerabilities may be triggered by enticing a user to request an excessively long URI from an RTSP server. Such a URI could be embedded in a playlist or possibly linked to from within a web page (if one of the players is configured as a handler for RTSP URIs).
Two more issues were also reported that could be exploited by a malicious RTSP server. One of the issues is exposed during session negotiation and the other issue is exposed when the clients receive RDT (Real Data Transfer) packets from the server.
These issues may permit remote attackers to execute arbitrary code in the context of the client user.
It should be noted that these issues are not present if support for realrtsp has been disabled.
Exploit / POC
MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities
Solution:
Slackware Linux has released advisory SSA:2004-124-03 dealing with this issue. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200405-24 dealing with this issue. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to upgrade their computers:
# emerge sync
# emerge -pv ">=media-video/mplayer-1.0_pre4"
# emerge ">=media-video/mplayer-1.0_pre4"
# emerge -pv ">=media-libs/xine-lib-1_rc4"
# emerge ">=media-libs/xine-lib-1_rc4"
These issues have been addressed in MPlayer 1.0pre4 and xine-lib 1-rc4.
xine xine-lib 1-rc2
xine xine-lib 1-beta7
xine xine-lib 1-beta3
xine xine-lib 1-rc3c
xine xine-lib 1-beta10
xine xine-lib 1-beta9
xine xine-lib 1-beta1
xine xine-lib 1-rc3a
xine xine-lib 1-beta2
xine xine-lib 1-beta8
xine xine-lib 1-beta4
xine xine-lib 1-beta11
xine xine-lib 1-rc3b
xine xine-lib 1-beta6
xine xine-lib 1-beta5
MPlayer MPlayer 1.0 pre3try2
Solution:
Slackware Linux has released advisory SSA:2004-124-03 dealing with this issue. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200405-24 dealing with this issue. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to upgrade their computers:
# emerge sync
# emerge -pv ">=media-video/mplayer-1.0_pre4"
# emerge ">=media-video/mplayer-1.0_pre4"
# emerge -pv ">=media-libs/xine-lib-1_rc4"
# emerge ">=media-libs/xine-lib-1_rc4"
These issues have been addressed in MPlayer 1.0pre4 and xine-lib 1-rc4.
xine xine-lib 1-rc2
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta7
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta3
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-rc3c
-
Slackware xine-lib-1rc4-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/x ine-lib-1rc4-i686-1.tgz -
Slackware xine-lib-1rc4-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ xine-lib-1rc4-i686-1.tgz -
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta10
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta9
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta1
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-rc3a
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta2
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta8
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta4
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta11
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-rc3b
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta6
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
xine xine-lib 1-beta5
-
xine xine-lib 1-rc4
http://xinehq.de/index.php/releases
MPlayer MPlayer 1.0 pre3try2
-
MPlayer MPlayer 1.0pre4
http://mplayer.dev.hu/homepage/design6/dload.html
References
MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities
References:
References:
- MPlayer Homepage (MPlayer)
- MPlayer News (MPlayer)
- xine Homepage (xine)
- XSA-2004-3 (xine)