April 2006
Three Gentoo Linux Security Advisories: 1. GLSA 200604-15 - xine-ui: Format string vulnerabilities 2. GLSA 200604-16 - xine-lib: Buffer overflow vulnerabilit 3. GLSA 200604-17 - Ethereal: Multiple vulnerabilities in protocol dissectors
ID: 00319
Ref: 314/2006
Date: 28 April 2006:14:17:45
Version: 1
Title: Three Gentoo Linux Security Advisories: 1. GLSA 200604-15 - xine-ui: Format string vulnerabilities 2. GLSA 200604-16 - xine-lib: Buffer overflow vulnerabilit 3. GLSA 200604-17 - Ethereal: Multiple vulnerabilities in protocol dissectors
Abstract:
Vendors affected: Gentoo
Operating systems affected: Gentoo
Applications affected: Gentoo
Title
=====
Three Gentoo Linux Security Advisories:
1. GLSA 200604-15 - xine-ui: Format string vulnerabilities
2. GLSA 200604-16 - xine-lib: Buffer overflow vulnerabilit
3. GLSA 200604-17 - Ethereal: Multiple vulnerabilities in protocol dissectors
Detail
======
1. Ludwig Nussel discovered that xine-ui incorrectly implements formatted
printing.
2. Federico L. Bossi Bonin discovered that when handling MPEG streams
xine-lib fails to make a proper boundary check of the input data
supplied by the user before copying it to an insufficiently sized
memory buffer.
3. Coverity discovered numerous vulnerabilities in versions of Ethereal
prior to 0.99.0.
1.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: xine-ui: Format string vulnerabilities
Date: April 26, 2006
Bugs: #130801
ID: 200604-15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Format string vulnerabilities in xine-ui may lead to the execution of
arbitrary code.
Background
==========
xine-ui is a skin-based user interface for xine. xine is a free
multimedia player. It plays CDs, DVDs, and VCDs, and can also decode
other common multimedia formats.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 media-video/xine-ui < 0.99.4-r5 >= 0.99.4-r5
Description
===========
Ludwig Nussel discovered that xine-ui incorrectly implements formatted
printing.
Impact
======
By constructing a malicious playlist file, a remote attacker could
exploit these vulnerabilities to execute arbitrary code with the rights
of the user running the application.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All xine-ui users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/xine-ui-0.99.4-r5"
References
==========
[ 1 ] CVE-2006-1905
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1905
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200604-15.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.0
2.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-16
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: xine-lib: Buffer overflow vulnerability
Date: April 26, 2006
Bugs: #128838
ID: 200604-16
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
xine-lib contains a buffer overflow vulnerability which may lead to the
execution of arbitrary code.
Background
==========
xine-lib is the xine core engine. xine is a free multimedia player. It
plays CDs, DVDs, and VCDs, and can also decode other common multimedia
formats.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 xine-lib < 1.1.2_pre20060328-r1 >= 1.1.2_pre20060328-r1
Description
===========
Federico L. Bossi Bonin discovered that when handling MPEG streams
xine-lib fails to make a proper boundary check of the input data
supplied by the user before copying it to an insufficiently sized
memory buffer.
Impact
======
A remote attacker could entice a user to play a specially-crafted MPEG
file, resulting in the execution of arbitrary code with the permissions
of the user running the application.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All xine-lib users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/xine-lib-1.1.2_pre20060328-r1"
References
==========
[ 1 ] CVE-2006-1664
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1664
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200604-16.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.0
3.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-17
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: Ethereal: Multiple vulnerabilities in protocol dissectors
Date: April 27, 2006
Bugs: #130505
ID: 200604-17
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Ethereal is vulnerable to numerous vulnerabilities, potentially
resulting in the execution of arbitrary code.
Background
==========
Ethereal is a feature-rich network protocol analyzer.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-analyzer/ethereal < 0.99.0 >= 0.99.0
Description
===========
Coverity discovered numerous vulnerabilities in versions of Ethereal
prior to 0.99.0, including:
* buffer overflows in the ALCAP (CVE-2006-1934), COPS (CVE-2006-1935)
and telnet (CVE-2006-1936) dissectors.
* buffer overflows in the NetXray/Windows Sniffer and Network
Instruments file code (CVE-2006-1934).
For further details please consult the references below.
Impact
======
An attacker might be able to exploit these vulnerabilities to crash
Ethereal or execute arbitrary code with the permissions of the user
running Ethereal, which could be the root user.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Ethereal users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/ethereal-0.99.0"
References
==========
[ 1 ] CVE-2006-1932
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1932
[ 2 ] CVE-2006-1933
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1933
[ 3 ] CVE-2006-1934
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1934
[ 4 ] CVE-2006-1935
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1935
[ 5 ] CVE-2006-1936
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1936
[ 6 ] CVE-2006-1937
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1937
[ 7 ] CVE-2006-1938
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1938
[ 8 ] CVE-2006-1939
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1939
[ 9 ] CVE-2006-1940
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1940
[ 10 ] Ethereal enpa-sa-00023
http://www.ethereal.com/appnotes/enpa-sa-00023.html
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200604-17.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.0