- ------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-15
- ------------------------------------------------------------------------
          PACKAGE : media-video/mplayer
          SUMMARY : Buffer Overflow Vulnerability
             DATE : 2003-09-27 21:37 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <=mplayer-0.91 =mplayer-1.0_pre1
    FIXED VERSION : =mplayer-0.92 =mplayer-1.0_pre1-r1
    GENTOO BUG ID : 29640
              CVE : none that we are aware of at this time
- ------------------------------------------------------------------------

SUMMARY:
 A remotely exploitable buffer overflow vulnerability was found in
 MPlayer. A malicious host can craft a harmful ASX header, and trick
 MPlayer into executing arbitrary code upon parsing that header.

 read the full advisory at:
    

SOLUTION:

 It is recommended that all Gentoo Linux users who are running
 media-video/mplayer upgrade to mplayer-0.92 as follows

 emerge sync
 emerge =media-video/mplayer-0.92
 emerge clean

 Additionally PaX users might want to /sbin/chpax -m /usr/bin/mplayer

- - - ---------------------------------------------------------------------
solar@gentoo.org
aliz@gentoo.org - GnuPG key is available at   
- - - ---------------------------------------------------------------------

Gentoo: media-video/mplayer Buffer overflow vulnerability

A remotely exploitable buffer overflow vulnerability was found in MPlayer

Summary


- ------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-15
- ------------------------------------------------------------------------
    FIXED VERSION : =mplayer-0.92 =mplayer-1.0_pre1-r1
    GENTOO BUG ID : 29640
- ------------------------------------------------------------------------
SUMMARY:
 A remotely exploitable buffer overflow vulnerability was found in
 MPlayer. A malicious host can craft a harmful ASX header, and trick
 MPlayer into executing arbitrary code upon parsing that header.

read the full advisory at:

SOLUTION:
It is recommended that all Gentoo Linux users who are running media-video/mplayer upgrade to mplayer-0.92 as follows
emerge sync emerge =media-video/mplayer-0.92 emerge clean
Additionally PaX users might want to /sbin/chpax -m /usr/bin/mplayer
solar@gentoo.org aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

Concerns

Severity
PACKAGE : media-video/mplayer
SUMMARY : Buffer Overflow Vulnerability
DATE : 2003-09-27 21:37 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <=mplayer-0.91 =mplayer-1.0_pre1
CVE : none that we are aware of at this time

Synopsis

Background

Affected Packages

Impact

Workaround

Related News