[UNIX] Mplayer Multiple Arbitrary Execution Vulnerabilities



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Mplayer Multiple Arbitrary Execution Vulnerabilities
------------------------------------------------------------------------


SUMMARY

"MPlayer is a movie player which runs on many systems (see the
documentation). It plays most MPEG/VOB, AVI, Ogg/OGM, VIVO, ASF/WMA/WMV,
QT/MOV/MP4, RealMedia, Matroska, NUT, NuppelVideo, FLI, YUV4MPEG, FILM,
RoQ, PVA files, supported by many native, XAnim, and Win32 DLL codecs. You
can watch VideoCD, SVCD, DVD, 3ivx, DivX 3/4/5 and even WMV movies.." Two
vulnerabilities have been discovered in MPlayer which allow attackers to
cause it to crash by tricking MPlayer into accessing a malformed IPv6
addresses or by responding to it with an arbitrary long CDDB entry.

DETAILS

Vulnerable Systems:
* MPlayer 1.0rc2 and SVN before r25824

Immune Systems:
* MPlayer 1.0rc2 and SVN after Sun Jan 20 20:43:46 2008 UTC

URL IPv6 Address Parsing Remote Heap Overflow:
A heap overflow condition exists in the parsing of IPv6 addresses,
allowing for arbitrary code execution.

CDDB Remote Stack Overflow:
A remote attacker may execute arbitrary code on a client machine by
causing a specially crafted CDDB response to be sent to the client.


ADDITIONAL INFORMATION

The information has been provided by Mu Security.
The original article can be found at:
<http://labs.musecurity.com/advisories/MU-200802-01.txt>
http://labs.musecurity.com/advisories/MU-200802-01.txt



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [UNIX] Remote Buffer Overflow Vulnerabilities in Real RTSP Streaming
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... joint advisory by the MPlayer and xine teams as the code in question is ... RTSP input plugin, ...
    (Securiteam)
  • [NEWS] MPlayer Buffer Overflow (asf_streaming)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... and trick MPlayer into executing arbitrary code upon parsing ... fully controllable EIP buffer overflow. ...
    (Securiteam)
  • [NEWS] MPlayer "ASF" File Handling Multiple Integer Overflows
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Improper handling of ASF files allows attackers to DoS MPlayer. ... The problem happen when allocating memory to copy data from an .asf file. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [UNIX] MPlayer Encoded URL Heap Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A remotely exploitable buffer overflow vulnerability was found in ... and trick MPlayer into executing arbitrary code ... Whilst requesting a file from a web server, MPlayer allocates a buffer to ...
    (Securiteam)
  • [UNIX] Buffer Overflow in GOCR
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... GOCR - open-source character recognition software is vulnerable to buffer ... An integer overflow leading to heap overflow, ... This vulnerability ...
    (Securiteam)