Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 218059
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Hanno Boeck <hanno@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
evil.mp3 file crashing xine application/octet-stream Hanno Boeck 2008-04-17 06:59 0000 128 bytes Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 218059 depends on: Show dependency tree
Bug 218059 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-04-17 06:57 0000
http://lists.grok.org.uk/pipermail/full-disclosure/2008-April/061539.html

(will attach sample)

------- Comment #1 From Hanno Boeck 2008-04-17 06:59:32 0000 -------
Created an attachment (id=150019) [details]
file crashing xine

------- Comment #2 From Pierre-Yves Rofes 2008-04-29 12:36:13 0000 -------
Any news here? we already have a pending GLSA for xine-lib (bug #213039 and bug
#214270), but with a vulnerability remaining, it's pointless.

------- Comment #3 From Robert Buchholz 2008-05-12 01:13:39 0000 -------
These are patches for CVE-2008-1878:
http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset;node=d0ced21e0cf2;style=gitweb
http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset;node=2d5efbbeb882;style=gitweb

It should make sense to include these patches:
http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset;node=fa5398bfd312521bea5cb8097d864da578943325;style=gitweb
http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset;node=b22d0d37f9f0096c40f2047d01c21f3a96067d8b;style=gitweb

Diego, are you rolling a new release soon? Otherwise, media-video: please
create an ebuild with the patches included.

------- Comment #4 From Raphael Marichez 2008-05-18 13:19:53 0000 -------
Hi Diego and media-video team,

our GLSA draft about xine-lib has been ready for several days now, and we are
still waiting for this bug being solved. Please tell us if you plan to include
the patches for CVE-2008-1878 very shortly, or if not.

------- Comment #5 From Hanno Boeck 2008-06-02 07:34:20 0000 -------
Hi, I tried to fix this issue, but it seems the upstream commit doesn't fix it
(xine-lib 1.1 branch still crashes). I'm in contact with diego to resolv this.

------- Comment #6 From Hanno Boeck 2008-06-07 17:35:43 0000 -------
xine-lib-1.1.12-r1 should fix the buffer overflow. There's another crash-bug,
so testing the evil.mp3 will still crash xine, but there's no overflow any
more.

------- Comment #7 From Alexis Ballier 2008-06-25 15:40:50 0000 -------
(In reply to comment #2)
> Any news here? we already have a pending GLSA for xine-lib (bug #213039 and bug
> #214270), but with a vulnerability remaining, it's pointless.
> 

pong

wasn't -r1 good enough ? anyway, 1.1.13 is in the tree now.

Changes:
* Security fixes:
  - Buffer overflow in the NSF demuxer which may allow remote attackers to
    cause a denial of service (crash) or possibly execute arbitrary code
    via an NSF file with a long title or copyright message. (CVE-2008-1878)
  - For extra safety against possible Integer overflows like the ones found
    in CVE-2008-1482, backport more calloc usage from 1.2 branch.
* Added MIME types and .mpp for musepack.
* Fixed display of some MJPEG streams (YUVJ420P).
* Deprecate xine_xmalloc() function, see src/xine-utils/utils.c for more
  information about the reason.
* Provide a useful implementation of xine_register_log_cb().
* New version of the JACK output plugin.

------- Comment #8 From Pierre-Yves Rofes 2008-07-06 18:37:02 0000 -------
thanks Alexis.

------- Comment #9 From Robert Buchholz 2008-07-06 22:15:35 0000 -------
Arches, please test and mark stable:
=media-libs/xine-lib-1.1.13
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"

------- Comment #10 From Jeroen Roovers 2008-07-07 00:58:00 0000 -------
Stable for HPPA.

------- Comment #11 From Brent Baude 2008-07-07 03:07:41 0000 -------
ppc64 and ppc done

------- Comment #12 From Markus Meier 2008-07-07 20:58:15 0000 -------
amd64/x86 stable

------- Comment #13 From Raúl Porcel 2008-07-09 11:19:12 0000 -------
ia64/sparc stable

------- Comment #14 From Tobias Klausmann 2008-07-14 17:10:24 0000 -------
Stable on alpha.

------- Comment #15 From Robert Buchholz 2008-08-06 00:31:49 0000 -------
GLSA 200808-01

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug