Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200408-01] MPlayer: GUI filename handling overflow


Vulnerability Assessment Details

[GLSA-200408-01] MPlayer: GUI filename handling overflow

Vulnerability Assessment Summary
MPlayer: GUI filename handling overflow

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200408-01
(MPlayer: GUI filename handling overflow)


The MPlayer GUI code contains several buffer overflow vulnerabilities, and
at least one in the TranslateFilename() function is exploitable.

Impact

By enticing a user to play a file with a carefully crafted filename an
attacker could execute arbitrary code with the permissions of the user
running MPlayer.

Workaround

To work around this issue, users can compile MPlayer without GUI support by
disabling the gtk USE flag. All users are encouraged to upgrade to the
latest available version of MPlayer.

References:
http://www.securityfocus.com/bid/10615/
http://www.open-security.org/advisories/5


Solution:
All MPlayer users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=media-video/mplayer-1.0_pre4-r7"
# emerge ">=media-video/mplayer-1.0_pre4-r7"


Network Security Threat Level: Medium


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2005 Michel Arboi

Cables, Connectors


Mini External OLED AMIGA Gotek Floppy Drive Emulator For Amiga 500/500+/600/1200 picture

Mini External OLED AMIGA Gotek Floppy Drive Emulator For Amiga 500/500+/600/1200

$39.20



Commodore Amiga 3000 030 25Mhz + Keyboard + Mouse - Amiga OS 3.2 - WORKS 100% picture

Commodore Amiga 3000 030 25Mhz + Keyboard + Mouse - Amiga OS 3.2 - WORKS 100%

$1599.99



Brand New Amiga 4000T Keyboard picture

Brand New Amiga 4000T Keyboard

$299.99



Amiga Aminet 10 February 96 1996 Commodore picture

Amiga Aminet 10 February 96 1996 Commodore

$13.20



Amiga 500 Gotek Custom Mount USB Floppy Emulator - Complete Kit with Gotek picture

Amiga 500 Gotek Custom Mount USB Floppy Emulator - Complete Kit with Gotek

$65.00



Commodore Amiga 1060 Side Car Expansion

Commodore Amiga 1060 Side Car Expansion "IBM PC EMULATOR" VERY RARE COLLECTIBLE

$1499.95



Commodore Amiga 500 with Original Box.   Power Supply Games and More  1 MEG No.2 picture

Commodore Amiga 500 with Original Box. Power Supply Games and More 1 MEG No.2

$462.36



Amiga MiniMig 2.0 - FPGA Amiga 500 with real 68000CPU picture

Amiga MiniMig 2.0 - FPGA Amiga 500 with real 68000CPU

$179.99



AMIGA 500 COMPUTER COMMODORE Complete in Box Powers/untested Good Condition picture

AMIGA 500 COMPUTER COMMODORE Complete in Box Powers/untested Good Condition

$370.00



Amiga 5.25 External DUAL SLIM Floppy Disk Drive VERY RARE picture

Amiga 5.25 External DUAL SLIM Floppy Disk Drive VERY RARE

$199.00



Discussions

No Discussions have been posted on this vulnerability.