mplayer
Inviato: lun 15 mag 2006, 17:44
Nel sito ho trovato la versione try2.
Dove avete recuperato la try3?
Grazie
M.
Dove avete recuperato la try3?
Grazie
M.
2006.02.15, Wednesday :: heap overflow in demuxer.h
posted by Roberto
Summary
A potential buffer overflow was found in the ASF demuxer, and further analysis showed that the bug was in some more generic code in demuxer.h, used to create and resize buffers. You can read the original bug report here media-video/mplayer ASF File Parsing Integer Overflow (CAN-2006-0579) on Gentoo Bugzilla.
Severity
High (arbitrary remote code execution under the user ID running the player) when streaming an ASF file from a malicious server, medium (local code execution under the user ID running the player) if you play a malicious ASF file locally. At the time the buffer overflow was fixed there was no known exploit.
Solution
A fix for this problem was committed to CVS on Sun Feb 12 09:28:09 2006 UTC, and enhanced in versions 1.89 and 1.90. Users of affected MPlayer versions should download a patch for MPlayer 1.0pre7try2 here or here or update to the latest version if they're using CVS.
Please note that we are not releasing an updated tarball with this fix at this moment. Since MPlayer 1.0pre7 is very old, we encourage you to upgrade to the CVS version.
If you need to stay with 1.0pre7, get the MPlayer 1.0pre7try2 tarball, apply the patch with the fix and recompile MPlayer.
If you mantain a binary package for MPlayer, please name the updated version MPlayer 1.0pre7try3.