Git-Url: 
http://git.frugalware.org/gitweb/gitweb.cgi?p=homepage-ng.git;a=commitdiff;h=c24a22e4c0b02d7e74c5523b3e4a33a951b812f4

commit c24a22e4c0b02d7e74c5523b3e4a33a951b812f4
Author: Miklos Vajna <[EMAIL PROTECTED]>
Date:   Sat Feb 23 23:38:06 2008 +0100

FSA370-mplayer

diff --git a/frugalware/xml/security.xml b/frugalware/xml/security.xml
index c8ceb4f..555e42c 100644
--- a/frugalware/xml/security.xml
+++ b/frugalware/xml/security.xml
@@ -27,6 +27,25 @@

<fsas>
<fsa>
+               <id>370</id>
+               <date>2008-02-23</date>
+               <author>vmiklos</author>
+               <package>mplayer</package>
+               <vulnerable>1.0rc1-8</vulnerable>
+               <unaffected>1.0rc1-9sayshell1</unaffected>
+               <bts>http://bugs.frugalware.org/task/2774</bts>
+               <cve>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0485
+                       
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0486
+                       
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0629
+                       
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0630</cve>
+               <desc>Some vulnerabilities have been reported in MPlayer, which 
can be exploited by malicious people to compromise a user's system.
+                       1) A boundary error exists within the 
libmpdemux/demux_audio.c file when parsing FLAC comments. This can be exploited 
to corrupt memory via a specially crafted FLAC file.
+                       2) An array indexing error exists within the 
libmpdemux/demux_mov.c file when parsing MOV file headers. This can be 
exploited to corrupt heap memory via a specially crafted MOV file.
+                       3) A boundary error exists within the 
"url_scape_string()" function in stream/url.c. This can be exploited to cause a 
buffer overflow via a specially crafted URL.
+                       4) A boundary error exists within the 
"cddb_parse_matches_list()" and "cddb_query_parse()" functions in 
stream/stream_cddb.c. This can be exploited to cause a stack-based buffer 
overflow via an overly long album title received from a CDDB server.
+               Successful exploitation allows execution of arbitrary 
code.</desc>
+       </fsa>
+       <fsa>
<id>369</id>
<date>2008-02-08</date>
<author>vmiklos</author>
_______________________________________________
Frugalware-git mailing list
[email protected]
http://frugalware.org/mailman/listinfo/frugalware-git

Reply via email to