GXINE Remote Hostname Format String Vulnerability
BID:13707
Info
GXINE Remote Hostname Format String Vulnerability
| Bugtraq ID: | 13707 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1692 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | yan feng <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
xine gxine 0.4.4 xine gxine 0.4.3 xine gxine 0.4.2 xine gxine 0.4.1 xine gxine 0.4 .0 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux -current |
| Not Vulnerable: | |
Discussion
GXINE Remote Hostname Format String Vulnerability
Gxine is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to securely implement a formatted printing function.
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.
Gxine is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to securely implement a formatted printing function.
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.
Exploit / POC
GXINE Remote Hostname Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GXINE Remote Hostname Format String Vulnerability
Solution:
Gentoo has released advisory GLSA 200505-19 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose media-video/gxine
Slackware Linux has released security advisory SSA:2005-203-04 addressing this issue. Please see the referenced advisory for further information.
Solution:
Gentoo has released advisory GLSA 200505-19 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose media-video/gxine
Slackware Linux has released security advisory SSA:2005-203-04 addressing this issue. Please see the referenced advisory for further information.
References
GXINE Remote Hostname Format String Vulnerability
References:
References: