MPlayer GUI File Name Buffer Overflow Vulnerability
BID:10615
Info
MPlayer GUI File Name Buffer Overflow Vulnerability
| Bugtraq ID: | 10615 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0659 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this issue is credited to c0ntex <[email protected]>. |
| Vulnerable: |
MPlayer MPlayer 1.0 pre4 MPlayer MPlayer 1.0 pre3try2 MPlayer MPlayer 1.0 pre3 MPlayer MPlayer 1.0 pre2 MPlayer MPlayer 1.0 pre1 MPlayer MPlayer 0.92.1 MPlayer MPlayer 0.92 MPlayer MPlayer 0.91 MPlayer MPlayer 0.90 rc series MPlayer MPlayer 0.90 pre series MPlayer MPlayer 0.90 MPlayer MPlayer 0.9 0rc4 MPlayer MPlayer HEAD CVS MPlayer MPlayer 0_92 CVS |
| Not Vulnerable: | |
Discussion
MPlayer GUI File Name Buffer Overflow Vulnerability
It has been reported that MPlayer when used with the graphical user interface (GUI) is affected by a buffer overflow vulnerability. This issue is due to a failure of the application to properly handle user-supplied strings when copying them into finite buffers.
Successful exploitation would immediately produce a denial of service condition in the affected process. This issue may also be leveraged to execute code on the affected system within the security context of the user running the vulnerable process.
It has been reported that MPlayer when used with the graphical user interface (GUI) is affected by a buffer overflow vulnerability. This issue is due to a failure of the application to properly handle user-supplied strings when copying them into finite buffers.
Successful exploitation would immediately produce a denial of service condition in the affected process. This issue may also be leveraged to execute code on the affected system within the security context of the user running the vulnerable process.
Exploit / POC
MPlayer GUI File Name Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MPlayer GUI File Name Buffer Overflow Vulnerability
Solution:
Gentoo has released advisory GLSA 200408-01 dealing with this issue. All MPlayer users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=media-video/mplayer-1.0_pre4-r7"
# emerge ">=media-video/mplayer-1.0_pre4-r7"
For more information please see the referenced vendor advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released advisory GLSA 200408-01 dealing with this issue. All MPlayer users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=media-video/mplayer-1.0_pre4-r7"
# emerge ">=media-video/mplayer-1.0_pre4-r7"
For more information please see the referenced vendor advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MPlayer GUI File Name Buffer Overflow Vulnerability
References:
References:
- MPlayer Homepage (MPlayer)
- MPlayer MeMPlayer.c (c0ntex
)