Xine-lib VideoCD And Text Subtitle Stack Overflow Vulnerabilities
BID:11206
Info
Xine-lib VideoCD And Text Subtitle Stack Overflow Vulnerabilities
| Bugtraq ID: | 11206 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 16 2004 12:00AM |
| Updated: | Sep 16 2004 12:00AM |
| Credit: | Announced by Michael Roitzsch <[email protected]>. |
| Vulnerable: |
xine xine-lib 0.99 xine xine-lib 1-rc5 xine xine-lib 1-rc4 xine xine-lib 1-rc3 xine xine-lib 1-rc2 xine xine 0.9.18 xine xine 1-rc5 xine xine 1-rc4 xine xine 1-rc3 xine xine 1-rc2 SuSE Linux 8.1 SuSE Linux 8.0 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 |
| Not Vulnerable: |
xine xine-lib 0.9.13 xine xine-lib 0.9.8 xine xine-lib 1-rc6a xine xine-lib 1-rc1 xine xine-lib 1-rc0 xine xine-lib 1-beta9 xine xine-lib 1-beta8 xine xine-lib 1-beta7 xine xine-lib 1-beta6 xine xine-lib 1-beta5 xine xine-lib 1-beta4 xine xine-lib 1-beta3 xine xine-lib 1-beta2 xine xine-lib 1-beta12 xine xine-lib 1-beta11 xine xine-lib 1-beta10 xine xine-lib 1-beta1 xine xine-lib 1-alpha xine xine 0.9.13 xine xine 0.9.8 xine xine 1-rc6a xine xine 1-rc1 xine xine 1-rc0 xine xine 1-beta9 xine xine 1-beta8 xine xine 1-beta7 xine xine 1-beta6 xine xine 1-beta5 xine xine 1-beta4 xine xine 1-beta3 xine xine 1-beta2 xine xine 1-beta12 xine xine 1-beta11 xine xine 1-beta10 xine xine 1-beta1 xine xine 1-alpha |
Discussion
Xine-lib VideoCD And Text Subtitle Stack Overflow Vulnerabilities
Two buffer overflows are reported to exist in Xine-lib. These issues are exploitable through malicious VideoCDs or subtitle text content, and may allow for the execution of arbitrary code in the context of the user invoking Xine. Attackers can overwrite critical memory structures and return addresses in order to control the flow of execution of the application.
The first vulnerability presents itself when the affected application attempts to read malicious ISO disk labels from VideoCDs. The second vulnerability presents itself when the affected application attempts to parse malicious text subtitle data.
Xine-lib versions 1-rc2 though 1-rc5 are reported vulnerable to these issues.
Two buffer overflows are reported to exist in Xine-lib. These issues are exploitable through malicious VideoCDs or subtitle text content, and may allow for the execution of arbitrary code in the context of the user invoking Xine. Attackers can overwrite critical memory structures and return addresses in order to control the flow of execution of the application.
The first vulnerability presents itself when the affected application attempts to read malicious ISO disk labels from VideoCDs. The second vulnerability presents itself when the affected application attempts to parse malicious text subtitle data.
Xine-lib versions 1-rc2 though 1-rc5 are reported vulnerable to these issues.
Exploit / POC
Xine-lib VideoCD And Text Subtitle Stack Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Xine-lib VideoCD And Text Subtitle Stack Overflow Vulnerabilities
Solution:
Version 1-rc6a of Xine-lib has been released, along with patches for older versions, to address these issues:
Gentoo has released an advisory (GLSA 200409-30) to address various issues in xine-lib. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=media-libs/xine-lib-1_rc6"
emerge ">=media-libs/xine-lib-1_rc6"
Mandrake has released an advisory (MDKSA-2004:105) to address various issue in xine-lib. Please see the referenced advisory for more information.
SuSE has released a security summary report (SUSE-SR:2004:001) to address these and other issues. The report indicates that fixes for these issues are available on the SuSE FTP server and also through the YaST Online Update utility. Customers are advised to peruse the referenced advisory for further details regarding obtaining and applying appropriate fixes.
xine xine-lib 1-rc2
xine xine-lib 1-rc4
xine xine 1-rc3
xine xine 1-rc4
xine xine-lib 1-rc3
xine xine-lib 1-rc5
xine xine 1-rc2
xine xine 1-rc5
xine xine 0.9.18
xine xine-lib 0.99
Solution:
Version 1-rc6a of Xine-lib has been released, along with patches for older versions, to address these issues:
Gentoo has released an advisory (GLSA 200409-30) to address various issues in xine-lib. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=media-libs/xine-lib-1_rc6"
emerge ">=media-libs/xine-lib-1_rc6"
Mandrake has released an advisory (MDKSA-2004:105) to address various issue in xine-lib. Please see the referenced advisory for more information.
SuSE has released a security summary report (SUSE-SR:2004:001) to address these and other issues. The report indicates that fixes for these issues are available on the SuSE FTP server and also through the YaST Online Update utility. Customers are advised to peruse the referenced advisory for further details regarding obtaining and applying appropriate fixes.
xine xine-lib 1-rc2
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc4
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc3
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc4
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc3
-
Mandrake lib64xine1-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64xine1-devel-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-aa-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-arts-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-arts-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-dxr3-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-esd-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-esd-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-flac-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-flac-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-gnomevfs-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-gnomevfs-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-plugins-1-0.rc3.6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-plugins-1-0.rc3.6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine-lib 1-rc5
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc2
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 1-rc5
-
xine cd_types.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/libc dio/cd_types.c?r1=1.2&r2=1.3&diff_format=u -
xine demux_sputext.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/dem ux_sputext.c?r1=1.36&r2=1.37&diff_format=u -
xine xine_decoder.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/libsputext/xin e_decoder.c?r1=1.84&r2=1.85&diff_format=u -
xine xineplug_inp_vcd.c patch
http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/vcd/xine plug_inp_vcd.c?r1=1.18&r2=1.22&diff_format=u -
xine xine-lib-1-rc6a.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc6a.tar.gz?downloa d
xine xine 0.9.18
-
SuSE xine-0.9.18-137.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/xine-0.9.18-137.i 586.patch.rpm -
SuSE xine-0.9.18-137.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/xine-0.9.18-137.i 586.rpm
xine xine-lib 0.99
-
SuSE xine-lib-0.99.rc0a-117.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/xine-lib-0.99.rc0 a-117.i586.patch.rpm -
SuSE xine-lib-0.99.rc0a-117.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/xine-lib-0.99 .rc0a-117.x86_64.patch.rpm -
SuSE xine-lib-0.99.rc3a-106.15.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/xine-lib-0.99.rc3 a-106.15.i586.patch.rpm -
SuSE xine-lib-0.99.rc3a-106.15.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/xine-lib-0.99 .rc3a-106.15.x86_64.patch.rpm -
SuSE xine-lib-0.99.rc0a-117.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/xine-lib-0.99.rc0 a-117.i586.rpm -
SuSE xine-lib-0.99.rc0a-117.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/xine-lib-0.99 .rc0a-117.x86_64.rpm -
SuSE xine-lib-0.99.rc3a-106.15.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/xine-lib-0.99.rc3 a-106.15.i586.rpm -
SuSE xine-lib-0.99.rc3a-106.15.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/xine-lib-0.99 .rc3a-106.15.x86_64.rpm
References
Xine-lib VideoCD And Text Subtitle Stack Overflow Vulnerabilities
References:
References:
- xine Homepage (xine)
- XSA-2004-4: multiple string overflows (Michael Roitzsch
)