xine-lib: User-assisted execution of arbitrary code
Gentoo Linux Security Advisory
||GLSA 201006-04 / xine-lib
||June 01, 2010
||June 01, 2010: 01
All supported architectures
#234777, #249041, #260069, #265250
Multiple vulnerabilities in xine-lib might result in the remote execution
of arbitrary code.
xine-lib is the core library package for the xine media player, and
other players such as Amarok, Codeine/Dragon Player and Kaffeine.
Multiple vulnerabilities have been reported in xine-lib. Please review
the CVE identifiers referenced below for details.
A remote attacker could entice a user to play a specially crafted video
file or stream with a player using xine-lib, potentially resulting in
the execution of arbitrary code with the privileges of the user running
There is no known workaround at this time.
All xine-lib users should upgrade to an unaffected version:
Code Listing 3.1: Resolution
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/xine-lib-126.96.36.199"
NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since April 10, 2009. It is likely that your system is
already no longer affected by this issue.