CVE-2008-0486
Published: 5 February 2008
Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.
Notes
Author | Note |
---|---|
jdstrand | according to http://xinehq.de/index.php/security, 1.1.1 and older are not affected |
Priority
Status
Package | Release | Status |
---|---|---|
mplayer Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
|
edgy |
Released
(2:0.99+1.0pre8-0ubuntu8.2)
|
|
feisty |
Released
(2:1.0~rc1-0ubuntu9.3)
|
|
gutsy |
Released
(2:1.0~rc1-0ubuntu13.2)
|
|
hardy |
Released
(2:1.0~rc2-0ubuntu9)
|
|
upstream |
Needed
|
|
Patches: other: https://bugs.launchpad.net/ubuntu/+source/mplayer/+bug/191488 vendor: http://www.debian.org/security/2008/dsa-1496 |
||
xine-lib Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(1.1.1+ubuntu2-7.7)
|
edgy |
Ignored
(end of life, was needed)
|
|
feisty |
Released
(1.1.4-2ubuntu3.1)
|
|
gutsy |
Released
(1.1.7-1ubuntu1.3)
|
|
hardy |
Not vulnerable
(1.1.11.1-1ubuntu3)
|
|
upstream |
Released
(1.1.10.1-1)
|
|
Patches: vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:046 vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:046-1 |