Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 128838
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 128838 depends on: Show dependency tree
Bug 128838 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-04-04 16:35 0000
Xine-Lib Malformed MPEG Stream Buffer Overflow Vulnerability

Xine-lib is susceptible to a buffer-overflow vulnerability. This issue is due
to the application's failure to properly bounds-check user-supplied input data
before copying it to an insufficiently sized memory buffer.

Successful exploits allow remote attackers to execute arbitrary machine code in
the context of the affected application.

Xine-lib version 1.1.1 is reportedly affected. Other versions may also be
affected, as well as all applications that use a vulnerable version of the
library.

Published:       Apr 04 2006 12:00AM
Credit:  Federico L. Bossi Bonin <fbossi@netcomm.com.ar> discovered this issue.

http://http://www.securityfocus.com/bid/17370

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-04-04 21:31:17 0000 -------
*** Bug 128855 has been marked as a duplicate of this bug. ***

------- Comment #2 From Raphael Marichez 2006-04-10 05:54:06 0000 -------
Hi,

it is an A2. We should have acted now.
Sadly, AFAIK, no fix is available upstream and no other distrib has released
any update yet. I'm not aware of any evolution on this issue. Has someone any
information ?

------- Comment #3 From Thierry Carrez (RETIRED) 2006-04-10 10:02:02 0000 -------
FYI the target delay is counted once the bug has left upstream status, since we
can't really fix it before.

------- Comment #4 From Raphael Marichez 2006-04-10 13:23:28 0000 -------
Sorry :)

Then let's wait and see !

------- Comment #5 From Thierry Carrez (RETIRED) 2006-04-15 05:29:17 0000 -------
Upstream is late

------- Comment #6 From Diego E. 'Flameeyes' Pettenò 2006-04-15 06:59:53 0000 -------
The 1.1.2_pre20060328 snapshot seems to be unaffected, at least the given
concept stream doesn't crash xine at all (while it does on 1.1.1-r5).

Despite being a CVS snapshot, that version appears to me quite stable, I'm
using it almost daily, for both Kaffeine (video playing) and amaroK (audio),
and I haven't hit any kind of problem (it might be considered more working than
the current 1.1.1 version in some aspects, like MKV demuxing).

At this point, I can think of removing it from package.mask and back in ~arch,
to be tested for a while..

------- Comment #7 From Diego E. 'Flameeyes' Pettenò 2006-04-21 09:54:08 0000 -------
Okay I know I added -r1 just yesterday, but if this is going to be pushed
stable, I'd rather see that marked stable as it _is_ finally stable. The main
issue with xine (crashes when mad was disabled) is now fixed, and authenticated
HTTP streams are fixed, too. I might say that this version is even more stable
than the current stable :)

So if a decision for pushing this has to be made, I suppose it should be okay
at this point in time.
Also, I didn't receive any "aaaargh my xine broke" kind of bugs after unmasking
and going to ~arch.

------- Comment #8 From Stefan Cornelius (RETIRED) 2006-04-21 10:06:38 0000 -------
ok, here we go: arches, please test and stable 1.1.2_pre20060328-r1, thank you.

------- Comment #9 From Thomas Cort (RETIRED) 2006-04-21 13:02:01 0000 -------
(In reply to comment #8)
> ok, here we go: arches, please test and stable 1.1.2_pre20060328-r1, thank you.

alpha stable.

------- Comment #10 From Gustavo Zacarias (RETIRED) 2006-04-21 13:43:35 0000 -------
sparc stable.

------- Comment #11 From Mark Loeser 2006-04-21 17:33:08 0000 -------
x86 done

------- Comment #12 From Markus Rothe 2006-04-22 02:36:33 0000 -------
stable on ppc64

------- Comment #13 From Thomas Cort (RETIRED) 2006-04-22 09:57:26 0000 -------
stable on amd64

------- Comment #14 From Tobias Scherbaum 2006-04-22 11:58:57 0000 -------
ppc stable

------- Comment #15 From Guy Martin 2006-04-22 15:12:19 0000 -------
Besides a gcc-4.1 bug, it's working perfectly on hppa :)

------- Comment #16 From Raphael Marichez 2006-04-23 01:12:37 0000 -------
Sorry for the last change.
This one is ready for GLSA.
arm & ia64 you can mark stable if you want, in order to benefit from the GLSA.

------- Comment #17 From Sune Kloppenborg Jeppesen 2006-04-26 10:42:04 0000 -------
GLSA 200604-16

arm, ia64 please don't forget to mark stable to benifit from the GLSA.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug