Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 339037 - media-video/mplayer: Arbitrary Offset Dereference (CVE-2010-3429)
Summary: media-video/mplayer: Arbitrary Offset Dereference (CVE-2010-3429)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.ocert.org/advisories/ocert...
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-09-28 14:58 UTC by Tim Sammut (RETIRED)
Modified: 2013-10-25 19:17 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2010-09-28 14:58:03 UTC
+++ This bug was initially created as a clone of Bug #339036 +++

From $url:

The libavcodec library, an open source video encoding/decoding library part of
the FFmpeg project, suffers from an arbitrary offset dereference vulnerability.

The vulnerability affects the flic file format parser, insufficient
restrictions on a writable buffer can be exploited to execute arbitrary code
via the heap memory. A specific flic file can be crafted to trigger the
vulnerability.

The MPlayer multimedia player is also affected as it statically includes
libavcodec, the flic codec can be disabled in codecs.conf configuration file in
order to workaround the issue.

The upstream fix is at:

http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=16c592155f117ccd7b86006c45aacc692a81c23b
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-11-10 10:31:09 UTC
I think now we have a full release from upstream, see
http://www.ffmpeg.org/releases/ffmpeg-0.6.1.release
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-10-14 03:15:12 UTC
The third party advisory at $URL lists:

MPlayer >= snapshot 2010-09-28

as fixed. Our stable is more recent than this, so moving this to [glsa]
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2013-10-25 19:17:07 UTC
This issue was resolved and addressed in
 GLSA 201310-13 at http://security.gentoo.org/glsa/glsa-201310-13.xml
by GLSA coordinator Sean Amoss (ackle).