MPlayer: Two heap overflow vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200504-19 / MPlayer |
| Release Date |
April 20, 2005 |
| Latest Revision |
May 22, 2006: 02 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| media-video/mplayer |
<
1.0_pre6-r4 |
>=
1.0_pre6-r4 |
All supported architectures
|
Related bugreports:
#89277
Synopsis
Two vulnerabilities have been found in MPlayer which could lead to the
remote execution of arbitrary code.
2.
Impact Information
Background
MPlayer is a media player capable of handling multiple multimedia file
formats.
Description
Heap overflows have been found in the code handling RealMedia RTSP and
Microsoft Media Services streams over TCP (MMST).
Impact
By setting up a malicious server and enticing a user to use its
streaming data, a remote attacker could possibly execute arbitrary code
on the client computer with the permissions of the user running
MPlayer.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All MPlayer users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/mplayer-1.0_pre6-r4"
|
4.
References
|