MiMMS Media Stream Handling Remote Buffer Overflow Vulnerability
BID:18608
Info
MiMMS Media Stream Handling Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 18608 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2200 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2006 12:00AM |
| Updated: | Jan 25 2007 04:29PM |
| Credit: | Anon Sricharoenchai has been credited for the discovery of this vulnerability |
| Vulnerable: |
xine xine-lib 1.1 xine xine-lib 1.0.1 xine xine-lib 1.0 Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 11.0 Slackware Linux -current MiMMS mimms 0.0.9 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian mimms 3.1 |
| Not Vulnerable: | |
Discussion
MiMMS Media Stream Handling Remote Buffer Overflow Vulnerability
MiMMS Media Stream Handling is prone to a buffer-overflow vulnerability that is caused by passing excessive data that may overflow a finite-sized internal memory buffer. A successful attack may result in memory corruption as memory adjacent to the buffer is overwritten with user-supplied data.
This issue may lead to a denial-of-service condition or to the execution of arbitrary code.
Version 0.0.9 of MiMMS Media Stream Handling is vulnerable to this issue; other versions may also be affected.
MiMMS Media Stream Handling is prone to a buffer-overflow vulnerability that is caused by passing excessive data that may overflow a finite-sized internal memory buffer. A successful attack may result in memory corruption as memory adjacent to the buffer is overwritten with user-supplied data.
This issue may lead to a denial-of-service condition or to the execution of arbitrary code.
Version 0.0.9 of MiMMS Media Stream Handling is vulnerable to this issue; other versions may also be affected.
Exploit / POC
MiMMS Media Stream Handling Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
MiMMS Media Stream Handling Remote Buffer Overflow Vulnerability
Solution:
Please see the references for vendor advisories and more information.
Slackware Linux 11.0
MiMMS mimms 0.0.9
Slackware Linux 10.0
Slackware Linux 10.1
Slackware Linux 10.2
Slackware Linux 9.1
Solution:
Please see the references for vendor advisories and more information.
Slackware Linux 11.0
-
Slackware xine-lib-1.1.3-i686-1_slack11.0.tgz
11.0:
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ xine-lib-1.1.3-i686-1_slack11.0.tgz
MiMMS mimms 0.0.9
-
Ubuntu libmms-dev_0.1-0ubuntu1.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/libm/libmms/libmms-dev_0.1 -0ubuntu1.1_amd64.deb -
Ubuntu libmms-dev_0.1-0ubuntu1.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/libm/libmms/libmms-dev_0.1 -0ubuntu1.1_i386.deb -
Ubuntu libmms-dev_0.1-0ubuntu1.1_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/libm/libmms/libmms-dev_0.1 -0ubuntu1.1_sparc.deb -
Ubuntu libmms0_0.1-0ubuntu1.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/libm/libmms/libmms0_0.1-0u buntu1.1_amd64.deb -
Ubuntu libmms0_0.1-0ubuntu1.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/libm/libmms/libmms0_0.1-0u buntu1.1_powerpc.deb -
Ubuntu libmms0_0.1-0ubuntu1.1_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/libm/libmms/libmms0_0.1-0u buntu1.1_sparc.deb
Slackware Linux 10.0
-
Slackware xine-lib-1.1.3-i686-1_slack10.0.tgz
Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ xine-lib-1.1.3-i686-1_slack10.0.tgz
Slackware Linux 10.1
-
Slackware xine-lib-1.1.3-i686-1_slack10.1.tgz
Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ xine-lib-1.1.3-i686-1_slack10.1.tgz
Slackware Linux 10.2
-
Slackware xine-lib-1.1.3-i686-1_slack10.2.tgz
Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ xine-lib-1.1.3-i686-1_slack10.2.tgz
Slackware Linux 9.1
-
Slackware xine-lib-1.1.3-i686-1_slack9.1.tgz
Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/x ine-lib-1.1.3-i686-1_slack9.1.tgz
References
MiMMS Media Stream Handling Remote Buffer Overflow Vulnerability
References:
References: