MPlayer strf header buffer overflow
| mplayer-strf-header-bo (22019) |
Description:
MPlayer is vulnerable to a buffer overflow caused by a vulnerability in handling strf stream headers for audio data. A remote attacker could send a specially-crafted AVI file containing a large value in the channel parameter to overflow a buffer and gain access to the target system.
Platforms Affected:
- Gentoo, Linux
- MandrakeSoft, Mandrake Linux 10.1
- MandrakeSoft, Mandrake Linux 10.1 X86_64
- MandrakeSoft, Mandrake Linux LE2005
- MandrakeSoft, Mandrake Linux LE2005 X86_64
- MandrakeSoft, Mandrake Linux Corporate Server 3.0
- MandrakeSoft, Mandrake Linux Corporate Server 3.0 X86_64
- MPlayer, MPlayer 1.0 pre7
- MPlayer, MPlayer 1.0 pre6-r4
- MPlayer, MPlayer 1.0 pre6-3.3.5-200501
Remedy:
For Gentoo Linux:
Refer to Gentoo Linux Security Announcement GLSA 2005-09-01 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Gain Access
References:
- Full-Disclosure Mailing List: Tue Aug 23 2005 - 21:34:49 CD, mplayer overflow at http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0772.html.
- MPlayer Web site, 2005.04.16, Saturday :: MPlayer 1.0pre7 released at http://www.mplayerhq.hu/homepage/design7/news.html.
- BID-14652: MPlayer Audio Header Buffer Overflow Vulnerability
- CVE-2005-2718: Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.
- GLSA-200509-01: MPlayer: Heap overflow in ad_pcm.c
- MDKSA-2005:158: Updated mplayer packages fix vulnerabilities
Reported:
Aug 23, 2005
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
