Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Slackware 10.2: 2005-283-01 Critical: Xine-Lib Code Execution Issue

slackware
Calendar Grey October 11, 2005
Scroller Slackware
New revisions for xine-lib rolled out to fix a vulnerability involving format strings that could enable code execution while playing media files.
New xine-lib packages are available for Slackware 9.1, 10.0, 10.1, 10.2, and -current to fix a security issue

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/xine-lib-1.0.3a-i686-1.tgz: Upgraded to xine-lib-1.0.3a. This fixes a format string bug where an attacker, if able to upload malicious information to a CDDB server and then get a local user to play a certain audio CD, may be able to run arbitrary code on the machine as the user running the xine-lib linked application. For more information, see: http://xinehq.de (* Security fix *)

Where Find New Packages

Updated package for Slackware 9.1:
Updated package for Slackware 10.0:
Updated package for Slackware 10.1:
Updated package for Slackware 10.2:
Updated package for Slackware -current:

MD5 Signatures

Slackware 9.1 package: a7e30f447b04a3d3cf27c2ecec1e8a0b xine-lib-1rc4-i686-2.tgz
Slackware 10.0 package: 09cef11a4e5f3bddcf23a86419e2ffcf xine-lib-1.0.3a-i686-1.tgz
Slackware 10.1 package: 5032e15ac5118effdfac672afa1c086f xine-lib-1.0.3a-i686-1.tgz
Slackware 10.2 package: ad6ed7f47bf6e7b6f656733c0c3cfe2a xine-lib-1.0.3a-i686-1.tgz
Slackware -current package: ad6ed7f47bf6e7b6f656733c0c3cfe2a xine-lib-1.0.3a-i686-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg xine-lib-1.0.3a-i686-1.tgz