what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Open Source CERT Security Advisory 2008.8

Open Source CERT Security Advisory 2008.8
Posted Aug 22, 2008
Authored by Will Drewry, Open Source CERT | Site ocert.org

The xine free multimedia player suffers from a number of vulnerabilities ranging in severity. The worst of these vulnerabilities results in arbitrary code execution and the least, in unexpected process termination. xine-lib versions 1.1.14 and below are affected.

tags | advisory, arbitrary, vulnerability, code execution
SHA-256 | 6ca037f9e8d51e3f07cc53661d3f13706366e6df2b215a8e1e7ad67c75a07c41

Open Source CERT Security Advisory 2008.8

Change Mirror Download

#2008-008 multiple heap overflows in xine-lib

Description:

The xine free multimedia player suffers from a number of vulnerabilities
ranging in severity. The worst of these vulnerabilities results in
arbitrary code execution and the least, in unexpected process
termination.

Five heap buffer overflows exist in parsing of real audio files, id3
tags, qt mov files, and matroska headers which all can result in
arbitrary code execution.

Three additional heap buffer overflows occur in mng, mod, and real
handling which are potentially exploitable.

Seven additional issues were identified in the input plugins as well as
the real, qt, and matroska demuxers which result in process termination
or memory corruption that may have wider implications.

The oCERT team was contacted by the Xine project requesting a review of
some code changes relating to memory allocations. These vulnerabilities
were the findings of this requested analysis. The full analysis text can
be found in the references below.

Affected version:

xine-lib <= 1.1.14

Fixed version:

xine-lib >= 1.1.15 [*]

* - see analysis text for more detail on fixes

Credit: Will Drewry, oCERT Team | Google Security Team.

CVE: TBD

Timeline:
2008-04-30: vendor contacts oCERT asking patch analysis
2008-05-06: analysis results in bug being found, test case sent upstream
2008-05-07: vendor submits second set of patches for analysis
2008-05-07: vendor provides issue private exposure to some vendors
2008-05-07: vendor proposes patch for the found security bug
2008-05-25: Full analysis results supplied to vendor and another PoC
2008-05-27: oCERT contacts vendor regarding timeline and coordination
2008-05-28: vendor asks for clarification
2008-06-09: oCERT contacts vendor offering help
2008-06-11: vendor supplies patches
2008-06-18: oCERT indicates that patches are incomplete
2008-06-21: vendor confirms receipt and looks in to options
2008-07-02: vendor indicates problem with a potential fix; oCERT replies
2008-07-28: vendor contact becomes unavailable
2008-08-11: oCERT attempts another contact with vendor
2008-08-12: new contact is confirmed
2008-08-14: xine-lib releases 1.1.15 with fixes (w/out oCERT knowledge)
2008-08-18: oCERT supplies all original findings and test cases again
2008-08-22: Ludwig Nussel notified oCERT regarding 1.1.15
2008-08-22: advisory release

References:
- Vulnerability analysis report:
http://www.ocert.org/analysis/2008-008/analysis.txt
- xine-1.1.15 release notes:
http://sourceforge.net/project/shownotes.php?release_id=619869&group_id=9655

Links:
- http://xinehq.de


--
Will Drewry <redpig@ocert.org>
oCERT Team :: http://ocert.org
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close