Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Slackware 10.2 Critical: Xine-Lib Buffer Overflow Security Update

slackware
Calendar Grey July 26, 2006
Scroller Slackware
Recent xine-lib updates address vulnerabilities in Slackware 10.2 and -current; essential fixes for buffer overflow concerns now released.
New xine-lib packages are available for Slackware 10.2 and -current to fix security issues

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/xine-lib-1.1.2-i686-1.tgz: Upgraded to xine-lib-1.1.2. According to xinehq.de's announcement: There are three security fixes: - CVE-2005-4048: possible buffer overflow in libavcodec (crafted PNGs); - CVE-2006-2802: possible buffer overflow in the HTTP plugin; - possible buffer overflow via bad indexes in specially-crafted AVI files. (* Security fix *)

Where Find New Packages

HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 10.2:
Updated package for Slackware -current:

MD5 Signatures

Slackware 10.2 package: d5d3dcd06fd6cc4f68d2a4717f507f21 xine-lib-1.1.2-i686-1.tgz
Slackware -current package: a82c9b20ccaec12f770cc1e4f63511d7 xine-lib-1.1.2-i686-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg xine-lib-1.1.2-i686-1.tgz