Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 46246
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Lars Wendler (Polynomial-C) <polynomial-c@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
klieber:
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 46246 depends on: Show dependency tree
Bug 46246 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-03-30 08:14 0000
The bugreport on mplayerhq is dated to 2004.03.30
see URL


Reproducible: Always
Steps to Reproduce:
1.
2.
3.

------- Comment #1 From Kurt Lieber 2004-03-30 08:16:22 0000 -------
media-video herd -- please review/comment/patch as appropriate.

------- Comment #2 From Rajiv Aaron Manglani 2004-03-30 21:36:54 0000 -------
more info:

http://www.mplayerhq.hu/homepage/design6/news.html

2004.03.30, Tuesday :: Exploitable remote buffer overflow vulnerability in the HTTP parser 
posted by Gabucino

Severity:
HIGH (if playing HTTP streaming content)
LOW (if playing only normal files)

Description:
A remotely exploitable buffer overflow vulnerability was found in MPlayer.  A malicious host can
craft a harmful HTTP header ("Location:"), and trick MPlayer  into executing arbitrary code upon
parsing that header.

MPlayer versions affected:
MPlayer 0.90pre series
MPlayer 0.90rc series
MPlayer 0.90
MPlayer 0.91
MPlayer 1.0pre1
MPlayer 1.0pre2
MPlayer 1.0pre3

MPlayer versions unaffected:
MPlayer releases before 0.60pre1
MPlayer 0.92.1
MPlayer 1.0pre3try2
MPlayer 0_92 CVS
MPlayer HEAD CVS
...
Patch availability:
A patch is available for all vulnerable versions  here.
http://www.mplayerhq.hu/MPlayer/patches/vuln02-fix.diff

------- Comment #3 From Patrick Kursawe 2004-03-31 00:26:33 0000 -------
Someone who was afraid to comment on this bug :-) gave the following links:
http://seclists.org/lists/bugtraq/2004/Mar/0323.html                            
http://seclists.org/lists/bugtraq/2004/Mar/0326.html

------- Comment #4 From Kurt Lieber 2004-03-31 00:51:56 0000 -------
Patrick -- can you please re-assign this back to security@gentoo.org once
you've got things patched?  Otherwise, we risk losing track of it.

Thanks.

------- Comment #5 From Kurt Lieber 2004-03-31 01:56:04 0000 -------
AMD64, PPC: please test mplayer-1.0_pre3-r5 and mark stable

------- Comment #6 From Kurt Lieber 2004-03-31 02:33:34 0000 -------
ignore my previous testing request.  I didn't properly understand how Patrick
patched things.

GLSA forthcoming.

------- Comment #7 From Kurt Lieber 2004-03-31 04:07:43 0000 -------
GLSA 200403-13

------- Comment #8 From Kurt Lieber 2004-03-31 04:35:46 0000 -------
*** Bug 46346 has been marked as a duplicate of this bug. ***

------- Comment #9 From Kurt Lieber 2004-04-05 08:22:38 0000 -------
*** Bug 46864 has been marked as a duplicate of this bug. ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug