Xine-lib DVD Subpicture Decoder Heap Overflow Vulnerability
BID:11205
Info
Xine-lib DVD Subpicture Decoder Heap Overflow Vulnerability
| Bugtraq ID: | 11205 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1379 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2004 12:00AM |
| Updated: | Jul 12 2006 04:38PM |
| Credit: | Announced by Michael Roitzsch <[email protected]>. |
| Vulnerable: |
xine xine-lib 0.9.8 xine xine-lib 0.9.8 xine xine-lib 1-rc5 xine xine-lib 1-rc4 xine xine-lib 1-rc3c xine xine-lib 1-rc3b xine xine-lib 1-rc3a xine xine-lib 1-rc3 xine xine-lib 1-rc2 xine xine-lib 1-rc1 xine xine-lib 1-rc0 xine xine-lib 1-beta9 xine xine-lib 1-beta8 xine xine-lib 1-beta7 xine xine-lib 1-beta6 xine xine-lib 1-beta5 xine xine-lib 1-beta4 xine xine-lib 1-beta3 xine xine-lib 1-beta2 xine xine-lib 1-beta12 xine xine 1-rc5 xine xine 1-rc4 xine xine 1-rc3b xine xine 1-rc3a xine xine 1-rc3 xine xine 1-rc2 xine xine 1-rc1 xine xine 1-rc1 xine xine 1-rc0a xine xine 1-rc0 xine xine 1-beta9 xine xine 1-beta8 xine xine 1-beta7 xine xine 1-beta6 xine xine 1-beta5 xine xine 1-beta4 xine xine 1-beta3 xine xine 1-beta2 xine xine 1-beta12 xine xine 1-beta11 xine xine 1-beta10 xine xine 1-beta1 xine xine 1-alpha Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 |
| Not Vulnerable: |
xine xine-lib 1-rc6a xine xine 1-rc6a |
Discussion
Xine-lib DVD Subpicture Decoder Heap Overflow Vulnerability
A buffer overflow in the DVD subpicture component, exploitable through malicious DVD or MPEG content, may allow for the execution of arbitrary code. The Xine-lib decoder converts subpicture data into an internal representation and stores it in dynamically allocated memory. A flaw in the calculation of required buffer space may result in the allocation of a buffer that is too small. Consequently, neighboring data in the heap may be corrupted when data is written to the buffer.
Attackers could exploit this vulnerability to write arbitrary words to nearly arbitrary locations in memory. The Linux and Windows dynamic memory-allocation subsystems may be more susceptible than BSD-based systems.
A buffer overflow in the DVD subpicture component, exploitable through malicious DVD or MPEG content, may allow for the execution of arbitrary code. The Xine-lib decoder converts subpicture data into an internal representation and stores it in dynamically allocated memory. A flaw in the calculation of required buffer space may result in the allocation of a buffer that is too small. Consequently, neighboring data in the heap may be corrupted when data is written to the buffer.
Attackers could exploit this vulnerability to write arbitrary words to nearly arbitrary locations in memory. The Linux and Windows dynamic memory-allocation subsystems may be more susceptible than BSD-based systems.
Exploit / POC
Xine-lib DVD Subpicture Decoder Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Xine-lib DVD Subpicture Decoder Heap Overflow Vulnerability
Solution:
The vulnerability is eliminated in version 1-rc6. The author has also made a source-code patch available:
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libspudec/spu.c?r1=1.77&r2=1.78&diff_format=u
Please see the referenced vendor advisories for more information.
xine xine-lib 1-rc2
xine xine-lib 1-rc3a
xine xine-lib 1-rc5
xine xine-lib 1-rc3b
xine xine 1-rc2
xine xine 1-rc3b
xine xine 1-rc3a
xine xine-lib 1-rc4
xine xine 1-rc3
xine xine-lib 1-rc3c
xine xine 1-rc4
xine xine-lib 1-rc3
xine xine 1-rc5
Solution:
The vulnerability is eliminated in version 1-rc6. The author has also made a source-code patch available:
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libspudec/spu.c?r1=1.77&r2=1.78&diff_format=u
Please see the referenced vendor advisories for more information.
xine xine-lib 1-rc2
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc3a
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc5
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc3b
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc2
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc3b
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc3a
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc4
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc3
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc3c
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc4
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc3
-
Mandrake lib64xine1-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64xine1-devel-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-aa-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-arts-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-arts-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-dxr3-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-esd-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-esd-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-flac-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-flac-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-gnomevfs-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-gnomevfs-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-plugins-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-plugins-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc5
-
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
References
Xine-lib DVD Subpicture Decoder Heap Overflow Vulnerability
References:
References:
- xine Homepage (xine)
- XSA-2004-5: heap overflow in DVD subpicture decoder (Michael Roitzsch
)