Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 159727
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jonathan Smith <smithj@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 159727 depends on: Show dependency tree
Bug 159727 blocks: 166476
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-01-02 08:39 0000
quoting from http://www.mplayerhq.hu/design7/news.html

The code mentioned in DSA 1244-1 is also included in MPlayer. A potential
buffer overflow was found in the code used to handle RealMedia RTSP streams.
When checking for matching asm rules, the code stores the results in a
fixed-size array, but no boundary checks are performed. This may lead to a
buffer overflow if the user is tricked into connecting to a malicious server.
Since the attacker can not write arbitrary data into the buffer, creating an
exploit is very hard; but a DoS attack is easily made.
Severity

High (DoS and eventually arbitrary remote code execution under the user ID
running the player) when setting up a RTSP session from a malicious server,
null if you do not use this feature. At the time the buffer overflow was fixed
there was no known exploit.
Solution

A fix for this problem was committed to SVN on Sun Dec 31 13:27:53 2006 UTC as
r21799. The fix involves three files: stream/realrtsp/asmrp.c,
stream/realrtsp/asmrp.h and stream/realrtsp/real.c. Users of affected MPlayer
versions should download a patch for MPlayer 1.0rc1 or update to the latest
version if they're using SVN.

------- Comment #1 From Raúl Porcel 2007-01-04 09:35:46 0000 -------
*** Bug 159990 has been marked as a duplicate of this bug. ***

------- Comment #2 From Raphael Marichez 2007-01-04 13:14:56 0000 -------
OK thanks Jonathan.

Do you know if 1.0_pre8 is affected too?

------- Comment #3 From Jonathan Smith 2007-01-04 13:19:04 0000 -------
I have no first hand knowledge of whether pre8 is affected, but I would assume
it is. rc1 is already stable on some arches, however, and it would make sense
to me to stablize rc1+fix on all arches.

------- Comment #4 From Matthias Geerdsen 2007-01-26 12:53:27 0000 -------
media-video, pls provide an updated ebuild including the patch

------- Comment #5 From Steve Dibb 2007-01-30 15:26:59 0000 -------
Added mplayer-1.0_rc1-r2 to the tree with included patch

------- Comment #6 From Daniel Pay 2007-02-01 13:31:49 0000 -------
*** Bug 164340 has been marked as a duplicate of this bug. ***

------- Comment #7 From Raphael Marichez 2007-02-10 21:21:28 0000 -------
Hi arches, please test and mark stable mplayer-1.0_rc1-r2 if appropriate,
thanks

------- Comment #8 From Christian Faulhammer 2007-02-11 09:58:04 0000 -------
x86 stable

------- Comment #9 From Tobias Scherbaum 2007-02-11 11:11:39 0000 -------
ppc stable

------- Comment #10 From René Nussbaumer 2007-02-11 21:56:54 0000 -------
stable on hppa

------- Comment #11 From Simon Stelling (RETIRED) 2007-02-11 23:59:26 0000 -------
amd64 stable

------- Comment #12 From Gustavo Zacarias (RETIRED) 2007-02-12 12:59:28 0000 -------
sparc stable.

------- Comment #13 From Bryan Østergaard (RETIRED) 2007-02-12 21:18:30 0000 -------
Stable on IA64.

------- Comment #14 From Bryan Østergaard (RETIRED) 2007-02-12 22:16:15 0000 -------
Stable on Alpha.

------- Comment #15 From Markus Rothe 2007-02-13 09:02:16 0000 -------
ppc64 stable

------- Comment #16 From Raphael Marichez 2007-02-27 15:57:40 0000 -------
GLSA 200702-11 , sorry for the delay

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug