LWN.net Logo

Conectiva alert CLA-2005:919 (xine-lib)

From:  Conectiva Updates <secure@conectiva.com.br>
To:  conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
Subject:  [CLA-2005:919] Conectiva Security Announcement - xine-lib
Date:  Wed, 19 Jan 2005 13:25:18 -0200

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -------------------------------------------------------------------------- PACKAGE : xine-lib SUMMARY : Fixes for xine-lib vulnerabilities DATE : 2005-01-19 13:24:00 ID : CLA-2005:919 RELEVANT RELEASES : 9, 10 - ------------------------------------------------------------------------- DESCRIPTION Xine[1] is a free multimedia player that plays back many of the most common multimedia formats available. Ariel Berkman discovered a buffer overflow vulnerability[2] in demux_aiff.c, where it reads specific input data into an array without checking the input size. iDefense noticed another buffer overflow vulnerability in the PNA_TAG handling code in pnm_get_chunk() becose it does not check if the input size is larger than the buffer size (CAN-2004-1187[3]) and also found, in this same function, an integer overflow vulnerability[4]. A remote attacker could specially craft a movie and/or convince a targeted user to connect to a malicious server, which could result in the execution of arbitrary code with the privileges of the user running any xine-lib frontend. SOLUTION It is recommended that all xine-lib users upgrade their packages. IMPORTANT: All applications that uses xine-lib must be restarted in order to finally close the vulnerabilities. REFERENCES 1.http://xinehq.de/ 2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1300 3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1187 4.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1188 UPDATED PACKAGES ftp://atualizacoes.conectiva.com.br/10/SRPMS/xine-lib-1.0... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-1.0.... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-alsa... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-arts... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-deve... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-dxr3... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-esd-... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-gnom... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-i18n... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-oggv... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-oss-... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-w32d... ftp://atualizacoes.conectiva.com.br/10/RPMS/xine-lib-xv-1... ftp://atualizacoes.conectiva.com.br/9/SRPMS/xine-lib-1.0.... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-1.0.0... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-aa-1.... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-alsa-... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-arts-... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-devel... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-esd-1... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-oggvo... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-oss-1... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-w32dl... ftp://atualizacoes.conectiva.com.br/9/RPMS/xine-lib-xv-1.... ADDITIONAL INSTRUCTIONS The apt tool can be used to perform RPM packages upgrades: - run: apt-get update - after that, execute: apt-get upgrade Detailed instructions regarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en - ------------------------------------------------------------------------- All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en - ------------------------------------------------------------------------- All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en - ------------------------------------------------------------------------- Copyright (c) 2004 Conectiva Inc. http://www.conectiva.com - ------------------------------------------------------------------------- subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFB7nvd42jd0JmAcZARAlFfAJ9/cIcdbNo66NuHe0GmMLy9IUwGZQCg1BYI U5s9PLOm8ERTrifm7LDuJxE= =wQCs -----END PGP SIGNATURE-----


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds