MPlayer 'demux_mov.c' Remote Code Execution Vulnerability
BID:27499
Info
MPlayer 'demux_mov.c' Remote Code Execution Vulnerability
| Bugtraq ID: | 27499 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0485 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | Apr 16 2008 12:29AM |
| Credit: | Felipe Manzano and Anibal Sacco from CORE Security Technologies are credited with the discovery of this vulnerability. |
| Vulnerable: |
MPlayer MPlayer 1.0rc2 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
MPlayer 'demux_mov.c' Remote Code Execution Vulnerability
MPlayer is prone to a remote code-execution vulnerability because it fails to sanitize certain 'MOV' file tags before using them to index heap memory.
An attacker can exploit this issue to execute arbitrary code, which can result in the complete compromise of the computer. Failed exploit attempts will result in a denial-of-service condition.
This issue affects MPlayer 1.0rc2; other versions may also be affected.
MPlayer is prone to a remote code-execution vulnerability because it fails to sanitize certain 'MOV' file tags before using them to index heap memory.
An attacker can exploit this issue to execute arbitrary code, which can result in the complete compromise of the computer. Failed exploit attempts will result in a denial-of-service condition.
This issue affects MPlayer 1.0rc2; other versions may also be affected.
Exploit / POC
MPlayer 'demux_mov.c' Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to open a malformed '.MOV' file.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploit code is available:
An attacker can exploit this issue by enticing an unsuspecting user to open a malformed '.MOV' file.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploit code is available:
Solution / Fix
MPlayer 'demux_mov.c' Remote Code Execution Vulnerability
Solution:
The vendor has committed fixes to the SVN repository. Please see the references for more information.
Solution:
The vendor has committed fixes to the SVN repository. Please see the references for more information.
References
MPlayer 'demux_mov.c' Remote Code Execution Vulnerability
References:
References:
- MPlayer Homepage (MPlayer)
- CORE-2008-0122: MPlayer arbitrary pointer dereference (Core Security Technologies Advisories
) - CORE-2008-0122 MPlayer arbitrary pointer dereference (Core Security Technologies )