CVE-2007-1246: MPlayer DMO buffer overflow

Bug #92968 reported by hexion
6
Affects Status Importance Assigned to Milestone
mplayer (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
William Grant
Edgy
Fix Released
Undecided
William Grant

Bug Description

Binary package hint: mplayer

http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.html

As I read in some security pages like www.hispasec.com (Spanish), there's a bug in mplayer rc1 and below that may put in risk the system. SVN version solves the problem.

ProblemType: Bug
Architecture: i386
Date: Sat Mar 17 00:51:53 2007
DistroRelease: Ubuntu 7.04
Uname: Linux patatilla 2.6.20-11-lowlatency #2 SMP PREEMPT Thu Mar 15 08:06:06 UTC 2007 i686 GNU/Linux

Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

Hi,

Thanks for your bug report. This issue has already been fixed in feisty:

mplayer (2:1.0~rc1-0ubuntu4) feisty; urgency=low

  * SECURITY UPDATE: DMO decoder heap overflow.
  * loader/dmo/DMO_VideoDecoder.c: added upstream fix.
  * References
    http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&r2=22204
    CVE-2007-1246

 -- Kees Cook <email address hidden> Tue, 6 Mar 2007 15:21:26 -0800

Changed in mplayer:
status: Unconfirmed → Fix Released
William Grant (wgrant)
Changed in mplayer:
assignee: nobody → fujitsu
status: New → In Progress
assignee: nobody → fujitsu
status: New → In Progress
Kees Cook (kees)
Changed in mplayer:
status: In Progress → Triaged
status: In Progress → Triaged
William Grant (wgrant)
Changed in mplayer:
status: Triaged → In Progress
Revision history for this message
William Grant (wgrant) wrote :

Here's a debdiff to fix all four outstanding issues in Dapper. I've tested the affected bits, and it all seems to work fine.

Revision history for this message
William Grant (wgrant) wrote :
Changed in mplayer:
status: Triaged → In Progress
Revision history for this message
Kees Cook (kees) wrote :

Thanks for preparing this! I've uploaded it to the security queue; it should be published shortly.

Changed in mplayer:
status: In Progress → Fix Committed
status: In Progress → Fix Committed
William Grant (wgrant)
Changed in mplayer:
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.