Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 161829 - media-video/xine-ui errors_create_window() Format String Vulnerability
Summary: media-video/xine-ui errors_create_window() Format String Vulnerability
Status: RESOLVED DUPLICATE of bug 161558
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://secunia.com/advisories/23709/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-01-12 21:58 UTC by Executioner
Modified: 2007-01-12 22:23 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Executioner 2007-01-12 21:58:07 UTC
Description:
A vulnerability has been reported in xine-ui, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a format string error within the "errors_create_window()" function in errors.c. This may be exploited to execute arbitrary code by e.g. tricking a user into opening a specially crafted playlist file.

The vulnerability is reported in version 0.99.4. Other versions may also be affected.

Solution:
Fixed in the CVS repository.

Reproducible: Didn't try
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2007-01-12 22:23:03 UTC
... don't drink and bugzilla ... sorry for bugspam
Comment 2 Stefan Cornelius (RETIRED) gentoo-dev 2007-01-12 22:23:47 UTC

*** This bug has been marked as a duplicate of bug 161558 ***