Gentoo: media-video/mplayer Buffer overflow vulnerability
Summary
- ------------------------------------------------------------------------ GENTOO LINUX SECURITY ANNOUNCEMENT 200309-15 - ------------------------------------------------------------------------ FIXED VERSION : =mplayer-0.92 =mplayer-1.0_pre1-r1 GENTOO BUG ID : 29640 - ------------------------------------------------------------------------ SUMMARY: A remotely exploitable buffer overflow vulnerability was found in MPlayer. A malicious host can craft a harmful ASX header, and trick MPlayer into executing arbitrary code upon parsing that header.
read the full advisory at:
SOLUTION:
It is recommended that all Gentoo Linux users who are running media-video/mplayer upgrade to mplayer-0.92 as follows
emerge sync emerge =media-video/mplayer-0.92 emerge clean
Additionally PaX users might want to /sbin/chpax -m /usr/bin/mplayer
solar@gentoo.org aliz@gentoo.org - GnuPG key is available at
Resolution
References
Availability
Concerns
Background