Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 161446 - <media-video/gxine-0.5.10 possible local exploit
Summary: <media-video/gxine-0.5.10 possible local exploit
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Media-video project
URL: http://sourceforge.net/project/showno...
Whiteboard:
Keywords:
Depends on: 173292
Blocks:
  Show dependency tree
 
Reported: 2007-01-10 23:52 UTC by Diego Elio Pettenò (RETIRED)
Modified: 2007-11-05 20:52 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Diego Elio Pettenò (RETIRED) gentoo-dev 2007-01-10 23:52:09 UTC
* SECURITY FIX (local exploit) 
  This version fixes a potential buffer overflow in gxine's server
  component and in gxine_client. This overflow would occur were $HOME
  sufficiently long - 94 bytes or more would cause socket creation or
  connection failure, and 242 bytes or more would cause a segfault or
  possible arbitrary code execution.

The ebuild is already in portage (a bit late, but when it was released I was unable to commit), and should be ready for stable.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2007-01-10 23:56:11 UTC
imho not a vuln. out of bounds stuff if $HOME is too big ... unless gxine is suid (which i wouldnt consider best practice), this seems like a non-issue because you cant gain anything?
Comment 2 Diego Elio Pettenò (RETIRED) gentoo-dev 2007-01-11 00:03:31 UTC
It is not suid, and yes, I find it farfetched too.. 242 bytes in $HOME sounds to be crazy anyway...
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-13 22:55:50 UTC
(In reply to comment #2)
> It is not suid, and yes, I find it farfetched too.. 242 bytes in $HOME sounds
> to be crazy anyway...
> 

Thanks for the report, but yes, indeed, this is really farfetched...

media-video may want to patch this but this is not a security issue. Reassigning.
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-08 22:47:24 UTC
Security, you can close it, as major arches (except ppc64) have .11 stable and it looks like a non-issue.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2007-11-05 20:52:15 UTC
(In reply to comment #4)
> Security, you can close it, as major arches (except ppc64) have .11 stable and
> it looks like a non-issue.

all stable, closing.