Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 46246

Summary: media-video/mplayer (all versions >=0.60pre1) Exploitable remote buffer overflow vulnerability in the HTTP parser
Product: Gentoo Security Reporter: Lars Wendler (Polynomial-C) (RETIRED) <polynomial-c>
Component: GLSA ErrorsAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: critical CC: andreas.w.simon, flash3001, jay, media-video, security, svein
Priority: Highest Keywords: SECURITY
Version: unspecifiedFlags: klieber: Pending-
Hardware: All   
OS: Linux   
URL: http://www.mplayerhq.hu/
Whiteboard:
Package list:
Runtime testing required: ---

Description Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2004-03-30 08:14:27 UTC
The bugreport on mplayerhq is dated to 2004.03.30
see URL


Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Kurt Lieber (RETIRED) gentoo-dev 2004-03-30 08:16:22 UTC
media-video herd -- please review/comment/patch as appropriate.
Comment 2 Rajiv Aaron Manglani (RETIRED) gentoo-dev 2004-03-30 21:36:54 UTC
more info:

http://www.mplayerhq.hu/homepage/design6/news.html

2004.03.30, Tuesday :: Exploitable remote buffer overflow vulnerability in the HTTP parser 
posted by Gabucino

Severity:
HIGH (if playing HTTP streaming content)
LOW (if playing only normal files)

Description:
A remotely exploitable buffer overflow vulnerability was found in MPlayer.  A malicious host can
craft a harmful HTTP header ("Location:"), and trick MPlayer  into executing arbitrary code upon
parsing that header.

MPlayer versions affected:
MPlayer 0.90pre series
MPlayer 0.90rc series
MPlayer 0.90
MPlayer 0.91
MPlayer 1.0pre1
MPlayer 1.0pre2
MPlayer 1.0pre3

MPlayer versions unaffected:
MPlayer releases before 0.60pre1
MPlayer 0.92.1
MPlayer 1.0pre3try2
MPlayer 0_92 CVS
MPlayer HEAD CVS
...
Patch availability:
A patch is available for all vulnerable versions  here.
http://www.mplayerhq.hu/MPlayer/patches/vuln02-fix.diff
Comment 3 Patrick Kursawe (RETIRED) gentoo-dev 2004-03-31 00:26:33 UTC
Someone who was afraid to comment on this bug :-) gave the following links:
http://seclists.org/lists/bugtraq/2004/Mar/0323.html                            
http://seclists.org/lists/bugtraq/2004/Mar/0326.html
Comment 4 Kurt Lieber (RETIRED) gentoo-dev 2004-03-31 00:51:56 UTC
Patrick -- can you please re-assign this back to security@gentoo.org once you've got things patched?  Otherwise, we risk losing track of it.

Thanks.
Comment 5 Kurt Lieber (RETIRED) gentoo-dev 2004-03-31 01:56:04 UTC
AMD64, PPC: please test mplayer-1.0_pre3-r5 and mark stable
Comment 6 Kurt Lieber (RETIRED) gentoo-dev 2004-03-31 02:33:34 UTC
ignore my previous testing request.  I didn't properly understand how Patrick patched things.

GLSA forthcoming.
Comment 7 Kurt Lieber (RETIRED) gentoo-dev 2004-03-31 04:07:43 UTC
GLSA 200403-13
Comment 8 Kurt Lieber (RETIRED) gentoo-dev 2004-03-31 04:35:46 UTC
*** Bug 46346 has been marked as a duplicate of this bug. ***
Comment 9 Kurt Lieber (RETIRED) gentoo-dev 2004-04-05 08:22:38 UTC
*** Bug 46864 has been marked as a duplicate of this bug. ***