MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Overflow Vulnerabilities
BID:11987
Info
MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11987 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2004 12:00AM |
| Updated: | Dec 16 2004 12:00AM |
| Credit: | Discovery is credited to anonymous researcher. |
| Vulnerable: |
xine xine-lib 1-rc7 xine xine-lib 1-rc6a xine xine-lib 1-rc6 xine xine-lib 1-rc5 xine xine-lib 1-rc4 xine xine-lib 1-rc3c xine xine-lib 1-rc3b xine xine-lib 1-rc3a xine xine-lib 1-rc3 xine xine-lib 1-rc2 xine xine-lib 1-rc1 xine xine-lib 1-rc0 xine xine 1-rc7 xine xine 1-rc6a xine xine 1-rc6 xine xine 1-rc5 xine xine 1-rc4 xine xine 1-rc3b xine xine 1-rc3a xine xine 1-rc3 xine xine 1-rc2 xine xine 1-rc1 xine xine 1-rc1 xine xine 1-rc0a xine xine 1-rc0 MPlayer MPlayer 1.0 pre5try1 MPlayer MPlayer 1.0 pre5 MPlayer MPlayer 1.0 pre4 MPlayer MPlayer 1.0 pre3try2 MPlayer MPlayer 1.0 pre3 MPlayer MPlayer 1.0 pre2 MPlayer MPlayer 1.0 pre1 MPlayer MPlayer 0.92.1 MPlayer MPlayer 0.92 MPlayer MPlayer 0.91 MPlayer MPlayer 0.90 rc series MPlayer MPlayer 0.90 pre series MPlayer MPlayer 0.90 MPlayer MPlayer 0.9 0rc4 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 |
| Not Vulnerable: |
xine xine-lib 1-rc8 xine xine 1-rc8 MPlayer MPlayer 1.0 pre5try2 |
Discussion
MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Overflow Vulnerabilities
Multiple remote, client side buffer overflow vulnerabilities reportedly affect xine-lib and MPlayer. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Multiple remote, client side buffer overflow vulnerabilities reportedly affect xine-lib and MPlayer. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Overflow Vulnerabilities
Symantec is currently aware that exploits have been developed to leverage some or all of these issues. The exploits are not known to be publicly available at this time.
Symantec is currently aware that exploits have been developed to leverage some or all of these issues. The exploits are not known to be publicly available at this time.
Solution / Fix
MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Overflow Vulnerabilities
Solution:
xine-lib 1-rc8 has been released dealing with this issue.
Mandrake Linux has released an advisory (MDKSA-2004:157) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo Linux has made an advisory available dealing with this and other issues. All MPlayer users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0_pre5-r5"
Please see the referenced Gentoo Linux advisory for more information.
Ubuntu has released an advisory USN-42-1 to address these issues. Please see the referenced advisory for more information.
Conectiva has released an advisory CLA-2005:910 to address various issues in MPlayer. Please see the referenced advisory for more information.
xine xine-lib 1-rc2
xine xine-lib 1-rc6a
xine xine-lib 1-rc6
xine xine-lib 1-rc3a
xine xine-lib 1-rc5
xine xine-lib 1-rc3b
xine xine-lib 1-rc1
xine xine-lib 1-rc7
xine xine-lib 1-rc4
xine xine-lib 1-rc3c
xine xine-lib 1-rc3
xine xine-lib 1-rc0
xine xine 1-rc5
MPlayer MPlayer 0.92
MPlayer MPlayer 1.0 pre3
MPlayer MPlayer 1.0 pre4
MPlayer MPlayer 1.0 pre5
MPlayer MPlayer 1.0 pre1
MPlayer MPlayer 1.0 pre2
MPlayer MPlayer 1.0 pre5try1
MPlayer MPlayer 1.0 pre3try2
Solution:
xine-lib 1-rc8 has been released dealing with this issue.
Mandrake Linux has released an advisory (MDKSA-2004:157) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo Linux has made an advisory available dealing with this and other issues. All MPlayer users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0_pre5-r5"
Please see the referenced Gentoo Linux advisory for more information.
Ubuntu has released an advisory USN-42-1 to address these issues. Please see the referenced advisory for more information.
Conectiva has released an advisory CLA-2005:910 to address various issues in MPlayer. Please see the referenced advisory for more information.
xine xine-lib 1-rc2
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc6a
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc6
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc3a
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc5
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc3b
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc1
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc7
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc4
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc3c
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc3
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine-lib 1-rc0
-
xine xine-lib-1-rc8.tar.gz
http://prdownloads.sourceforge.net/xine/xine-lib-1-rc8.tar.gz
xine xine 1-rc5
-
Ubuntu libxine-dev_1-rc5-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine-dev_1-r c5-1ubuntu2.1_amd64.deb -
Ubuntu libxine-dev_1-rc5-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine-dev_1-r c5-1ubuntu2.1_i386.deb -
Ubuntu libxine-dev_1-rc5-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine-dev_1-r c5-1ubuntu2.1_powerpc.deb -
Ubuntu libxine1_1-rc5-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine1_1-rc5- 1ubuntu2.1_amd64.deb -
Ubuntu libxine1_1-rc5-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine1_1-rc5- 1ubuntu2.1_i386.deb -
Ubuntu libxine1_1-rc5-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine1_1-rc5- 1ubuntu2.1_powerpc.deb
MPlayer MPlayer 0.92
-
Conectiva mplayer-0.92-28594U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mplayer-0.92-28594U90_2cl.i 386.rpm -
Conectiva mplayer-doc-0.92-28594U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mplayer-doc-0.92-28594U90_2 cl.i386.rpm
MPlayer MPlayer 1.0 pre3
-
Mandrake lib64postproc0-1.0-0.pre3.14.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64postproc0-devel-1.0-0.pre3.14.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libdha0.1-1.0-0.pre3.14.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libpostproc0-1.0-0.pre3.14.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libpostproc0-devel-1.0-0.pre3.14.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mencoder-1.0-0.pre3.14.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mencoder-1.0-0.pre3.14.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-1.0-0.pre3.14.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-1.0-0.pre3.14.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-gui-1.0-0.pre3.14.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-gui-1.0-0.pre3.14.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
MPlayer MPlayer 1.0 pre4
-
Conectiva mplayer-1.0pre6-73507U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mplayer-1.0pre6-73507U10_2 cl.i386.rpm -
Conectiva mplayer-doc-1.0pre6-73507U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mplayer-doc-1.0pre6-73507U 10_2cl.i386.rpm -
Conectiva mplayer-skins-1.0pre6-73507U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mplayer-skins-1.0pre6-7350 7U10_2cl.i386.rpm -
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
MPlayer MPlayer 1.0 pre5
-
Mandrake libdha1.0-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libdha1.0-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libpostproc0-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libpostproc0-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libpostproc0-devel-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libpostproc0-devel-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mencoder-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mencoder-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-gui-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mplayer-gui-1.0-0.pre5.7.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
MPlayer mmst_fix_20041215.diff
http://www1.mplayerhq.hu/MPlayer/patches/mmst_fix_20041215.diff -
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
MPlayer MPlayer 1.0 pre1
-
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
MPlayer MPlayer 1.0 pre2
-
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
MPlayer MPlayer 1.0 pre5try1
-
MPlayer bmp_fix_20041215.diff
http://www1.mplayerhq.hu/MPlayer/patches/bmp_fix_20041215.diff -
MPlayer mp3_fix_20041215.diff
http://www1.mplayerhq.hu/MPlayer/patches/mp3_fix_20041215.diff -
MPlayer pnm_fix_20041215.diff
http://www1.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff -
MPlayer rtsp_fix_20041215.diff
http://www1.mplayerhq.hu/MPlayer/patches/rtsp_fix_20041215.diff -
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
MPlayer MPlayer 1.0 pre3try2
-
MPlayer MPlayer 1.0pre5try2
http://www1.mplayerhq.hu/homepage/design7/news.html
References
MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Overflow Vulnerabilities
References:
References:
- MPlayer Bitmap Parsing Remote Heap Overflow Vulnerability (iDEFENSE)
- MPlayer Homepage (MPlayer)
- MPlayer News (MPlayer)
- MPlayer Remote RTSP Heap Overflow Vulnerability (iDEFENSE)
- xine 1-rc8 Change Log (xine)
- xine Homepage (xine)
- iDEFENSE Security Advisory 12.16.04: MPlayer Bitmap Parsing Remote Heap Overflow (iDEFENSE Security Advisory
) - iDEFENSE Security Advisory 12.16.04: MPlayer Remote RTSP HeapOverflow Vuln (iDEFENSE Security Advisory
)