Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 195308 - media-sound/alsaplayer Vorbis comment buffer overflow (CVE-2007-5301)
Summary: media-sound/alsaplayer Vorbis comment buffer overflow (CVE-2007-5301)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27117/
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-10-10 00:03 UTC by Robert Buchholz (RETIRED)
Modified: 2007-10-10 22:42 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-10-10 00:03:15 UTC
According to Secunia:
  Some vulnerabilities have been reported in AlsaPlayer, which
  potentially can be exploited by malicious people to compromise a
  user's system.

  The vulnerabilities are caused due to boundary errors in the vorbis
  input plug-in when processing .OGG files. These can be exploited to
  cause buffer overflows via a specially crafted .OGG file with overly
  long comments.

  Successful exploitation may allow execution of arbitrary code.
  
  Solution:
  The vendor has released 0.99.80-rc3, which fixes the
  vulnerabilities.
  
  Provided and/or discovered by:
  The vendor credits Erik Sjölund.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-10-10 00:05:52 UTC
0.99.80-rc3 is already in the tree, 0.99.80-rc4 was released as a bugfix today.

Sound, please advise for a fixed version to stable.
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2007-10-10 15:03:29 UTC
(In reply to comment #1)
> 0.99.80-rc3 is already in the tree, 0.99.80-rc4 was released as a bugfix today.
> 
> Sound, please advise for a fixed version to stable.
> 

Yes, we have -rc3 in tree, but this has never been stable, so status should be ~2.
Also, the said vulnerability has been fixed in -rc3, not -rc4, so nothing has to be done here wrt security. -rc4 seems to fix other bugs, not this one.

Closing, please re-open in case I'm fatally wrong.
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2007-10-10 18:51:34 UTC
And rc4 is in tree now.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-10-10 22:42:43 UTC
(In reply to comment #2)
> Yes, we have -rc3 in tree, but this has never been stable, so status should be
> ~2.

My bad, need new pair of eyes.