Moritz Jodeit discovered that the DirectShow loader of Xine did not correctly validate the size of an allocated buffer. By tricking a user into opening a specially crafted media file, an attacker could execute arbitrary code with the user's privileges. . =========================================================== Ubuntu Security Notice USN-435-1 March 12, 2007 xine-lib vulnerability CVE-2007-1387 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: libxine1c2 1.0.1-1ubuntu10.9 Ubuntu 6.06 LTS: libxine-main1 1.1.1+ubuntu2-7.7 Ubuntu 6.10: libxine1 1.1.2+repacked1-0ubuntu3.4 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Moritz Jodeit discovered that the DirectShow loader of Xine did not correctly validate the size of an allocated buffer. By tricking a user into opening a specially crafted media file, an attacker could execute arbitrary code with the user's privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 12233 675e1e62de2463b908fd32aeb9bfe60a Size/MD5: 1187 f9cdbdaba61da69e0b938dce158b0f3d Size/MD5: 7774954 9be804b337c6c3a2e202c5a7237cb0f8 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 109360 2fdbe1a14a39938370da76ba8bab0536 Size/MD5: 3611982 be994d0cc19f633ec74871cbd8a8d354 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 109366 7b4eca37fe190aa0efbab7cfe66d6dcb Size/MD5: 4005084 2826411084dff3fe99d72478646bc9ed powerpc architecture (Apple MacintoshG3/G4/G5) Size/MD5: 109354 8748b83cbdca49037a48236bf0a29192 Size/MD5: 3850630 4fe2ded6b53b4f814cecef7929e94643 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 109372 01d4c3f30fea1f692476f92560c18e2b Size/MD5: 3695886 c272d0b130739cbb690c2916ef246880 Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 19938 47e5b5f3b185adb45ad836e183a95c46 Size/MD5: 1113 143dcfd0208da129a9f6b553be5774be Size/MD5: 6099365 5d0f3988e4d95f6af6f3caf2130ee992 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 115898 155554542eec0dab285f5cc34b9704bf Size/MD5: 2615330 5cf4471e1563637f4d9f6b084b6b365a i386 architecture (x86 compatible Intel/AMD) Size/MD5: 115910 05ac35f926ba3f47d0d2eba8875bd3f8 Size/MD5: 2934426 3206757c9cf743813477ff214be1e769 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 115900 2f093ac6c4b3a0709a054ea9daca3a27 Size/MD5: 2725058 a0cc602a29cc664c32d0cf5694112683 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 115904 8011e1182c9ae79001083f4215cc208d Size/MD5: 2591836 cc1d268ee97f26872181c53c35323147 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 71623 ebe35a66a8d80fb8425d04667aa2dd7a Size/MD5: 1445 fbd4b9208b9aa1ae17ffb695d8a4a1f8 Size/MD5: 4583422 9c05a6397838e4e2e9c419e898e4b930 Architecture independent packages: Size/MD5: 39094 b038215bac1e84adc156a310d15c4caf amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 119040 3f1ec2c36475a53f39fa9d9bc2b57c3f Size/MD5: 3443132 57f239a84d5b64ec8e69138771bb552e Size/MD5: 2914616 8f3917f4a14166c826c3f6af13e899d3 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 119036 707d317b42b46693e62ed780b75447a2 Size/MD5: 377210295e2953730396910d2779014b1162cad Size/MD5: 3222320 6755a5b24b420e33913ee87e8ba79506 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 119048 abeed7884e45749fb1a5f3ba63e343d2 Size/MD5: 3469630 2dd5e21da5efcc1905e4de5949e6d551 Size/MD5: 3043218 5f14c87b113723ebd45d869fdd691679 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 119050 ca4592904b009e44625953027da5b23b Size/MD5: 3136760 cc8d9ce0cdf296eca70284609fe7642f Size/MD5: 2857100 0f8e4b35211aebfbcc2bdb2cc12e6c4d . Essential security patch released for xine on Ubuntu addressing buffer overflow security flaws that impact various versions.. Xine Security Patch, Ubuntu Xine Update, Buffer Overflow Threat. . Severity: Critical. LinuxSecurity.com Team
Moritz Jodeit discovered that the DMO loader of Xine did not correctly validate the size of an allocated buffer. By tricking a user into opening a specially crafted media file, an attacker could execute arbitrary code with the user's privileges.. =========================================================== Ubuntu Security Notice USN-433-1 March 09, 2007 xine-lib vulnerability CVE-2007-1246 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: libxine1c2 1.0.1-1ubuntu10.8 Ubuntu 6.06 LTS: libxine-main1 1.1.1+ubuntu2-7.6 Ubuntu 6.10: libxine1 1.1.2+repacked1-0ubuntu3.3 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Moritz Jodeit discovered that the DMO loader of Xine did not correctly validate the size of an allocated buffer. By tricking a user into opening a specially crafted media file, an attacker could execute arbitrary code with the user's privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 12146 b32c486037c9bd487f47677d77057aad Size/MD5: 1187 e4c778b992408ec8e46e5500921545af Size/MD5: 7774954 9be804b337c6c3a2e202c5a7237cb0f8 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 109296 92a59b50d859f12affc42fee457ed93f Size/MD5: 3611908 9e6f2c0dad7b1050a71d1f29d3537ec1 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 109306 3224a1a8c0c259b90add235d58d10a7a Size/MD5: 4005002 81fd17d5eabfa12a3dea0d9c8fd79d7f powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 109320 eb1a5685b7288b8cc9ef6ae09d422aec Size/MD5: 3850506 7801ba1b96b888c38b4e72f8fb4ccee1 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 109312 22805f01c94ced268bd12cf951447af4 Size/MD5: 3695682 e0fbc0aa0791685943a5094ea6519b2d Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 19845 149027147eff0f72e1d0af9faa0cd6cf Size/MD5: 1113 6fdbc64e22ad7511a80cba1ea840b534 Size/MD5: 6099365 5d0f3988e4d95f6af6f3caf2130ee992 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 115856 6146578aeeecdf61742b90dca3a97155 Size/MD5: 2615268 a6cff8bccebfbe51d7b3a6916d9250b1 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 115852 6b404dc405aefcac89ec3eec339f25a0 Size/MD5: 2934402 ea3a45814952437ac9f792cf1e7586b3 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 115860 1484daaeb0459a88c1760a1330397e52 Size/MD5: 2724986 889c6b454382dd63cd89020c87faf547 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 115860 b43491e3060c813b3530664cca2acd30 Size/MD5: 2591802 1e116a509bfd2b93588c48f665b78055 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 71537 8eb0120c16f4a7fa6a104906b453f51a Size/MD5: 1445 0a0fb0af663abf737e59cb67099e45ef Size/MD5: 4583422 9c05a6397838e4e2e9c419e898e4b930 Architecture independent packages: Size/MD5: 39034 4df368ac302eb48b666e8324529fa056 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 118968 17df05fc2764c33e4ba5615cf8962c2a Size/MD5: 3442878 b4a5d4fc2bcd737cf0b63d8d3a1ad4b1 Size/MD5: 2914566 91c324fe56add73266c33cbf38bc4536 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 118966 7c3bf270fba86dee9af4830cf36f41c8 Size/MD5: 3772104b85545a9e2aa6b60165d4bd76c8057d3 Size/MD5: 3222286 14d569c60f5ffcd329ff5d9069ede6d9 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 118974 a43b661831de4510c30f1c0b96bbfa66 Size/MD5: 3469556 e27b2c49a649493bc9a93919475af667 Size/MD5: 3043210 a4cca521e0eff186d3c19a6c96eba3ce sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 118978 c993d877a95c8e0a48d610b4883cf9e2 Size/MD5: 3136598 57d6199ddad2e55bb5d7c0673c7ed5a2 Size/MD5: 2857016 c79d6bac788a4c0fe262ada727b42c60 . Ubuntu Security Notice USN-433-1 March 09, 2007 xine-lib vulnerability CVE-2007-1246 A security issu. moritz, jodeit, loader, correctly, validate, alloc. . LinuxSecurity.com Team
This update fixes several format string bugs that can be exploited remotely This update fixes several format string bugs that can be exploited remotely with user-assistance to execute arbitrary code. with user-assistance to execute arbitrary code. Since SUSE Linux version 10.1 format string bugs are not exploitable anymore. (CVE-2007-0017)2) Solution or Work-Around. -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SUSE Security Announcement Package: xine-ui,xine-lib,xine-extra,xine-devel Announcement ID: SUSE-SA:2007:013 Date: Tue, 23 Jan 2007 08:00:00 +0000 Affected Products: SUSE LINUX 9.3 SUSE LINUX 10.0 SUSE LINUX 10.1 openSUSE 10.2 SUSE SLED 10 SLE SDK 10 Vulnerability Type: remote code execution Severity (1-10): 4 SUSE Default Package: no Cross-References: CVE-2007-0017 Content of This Advisory: 1) Security Vulnerability Resolved: format string bug Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: none 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion This update fixes several format string bugs that can be exploited remotely with user-assistance to execute arbitrary code. Since SUSE Linux version 10.1 format string bugs are not exploitable anymore. (CVE-2007-0017) 2) Solution or Work-Around No temporary work-around known. 3) Special Instructions and Notes none 4)Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. x86 Platform: openSUSE 10.2: 2cacbb4f4e177362149518481480165a 73cbdd8d443596547875804bd8e2ca8f 2114f7c6a4c8351adab588c173419778 5d4dd945a812ba0b17619c267ec8f2b5 SUSE LINUX 10.1: 3eb1465401e5e1c6f36d8e2d7ca3e114 e2fbf53b629e835dbc2558e87fabf926 d710db4b4d20f7ea4485d16845cb4be2 SUSE LINUX 10.0: 06753ebd3608223077c95c01f8bc3122 60ab4fd7c193d687d9484e5691aa3f01 4bc3f28d7e600fbb78c65f6b0dcfc436 SUSE LINUX 9.3: c944ed72f913771f0c2300883573e111 cee2a8a9669b429dde4e465e83aae70f Power PC Platform: openSUSE 10.2: a1fcfa82deed685446a213439639a579 bc2dcf2266dbb56b1a0291209aad2dd7 SUSE LINUX 10.1: c337440571123263478dd2a64059a4e8 3cf476901522d7b5abd5bf3cb18484a9 a9e762bad246963a7564c1f36a5f0392 SUSE LINUX 10.0: 930dc314de3ab49a8655e6cdb89ff50d ddd255708abfb433a3497d790491be55 827125d558472b685f0f1843d0eb3850 x86-64 Platform: openSUSE 10.2: 1dac6b23d257670ca7182f018c12a69b 11dae8e2ecb5a78eb6b1cd39713f6322 519480f44a28d4e3cab37aceca7e7c13 3b5db06dab41a4ff2a53d22b3f6f6238 b1a06bf5fd93c905bf5008859c88690d aa85b56d559aca4960693bad80a451bd SUSE LINUX10.1: 72f6cfc29f428a5d7dc40fbcb285cfe6 34382ef5b0ec94524678bdf842a21ecb 316fd37892ef25073cf9d6ae11fb510b ee0a3ce52f3bf431ced82dbd0148890c SUSE LINUX 10.0: 83094481db18fb55447a19b86db281ff 0e1b36454127be6815d1f52325ee1a70 45829c44efd83afaefe570d81f8a7568 bfe5d54a07d28cb9fef528c0257d4db7 SUSE LINUX 9.3: e829f9cbd5e02a0498f03a2180b57963 064665c8b3ac38f71634734c101f1602 8e7011003db37a1799bbd531ae957a28 Sources: openSUSE 10.2: f92b96c21a6e45ede2faa81c9efade83 ed0382a57f117bcf04236ca660092afe SUSE LINUX 10.1: 1d347a598b2e8dfc5eaa4f7b9c951242 SUSE LINUX 10.0: d1d2036b46056a00b3c5a0cee5371ad8 SUSE LINUX 9.3: 02ae3f6c9a88ec0aabcce701bba20542 Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SLE SDK 10 http://support.novell.com/techcenter/psdb/3850f4cb30959892275d84ebf0b1dfc6.html SUSE SLED 10 http://support.novell.com/techcenter/psdb/3850f4cb30959892275d84ebf0b1dfc6.html ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: none ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package: 1) Using the internal gpg signatures of the rpm package 2) MD5 checksums as provided in this announcement 1) The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
New xine packages are available for Slackware 9.1 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] xine security update (SSA:2004-111-01) New xine packages are available for Slackware 9.1 and -current to fix security issues. Here are the details from the Slackware 9.1 ChangeLog: +--------------------------+ Tue Apr 20 19:01:58 PDT 2004 patches/packages/xine-lib-1rc3c-i686-1.tgz: Upgraded to xine-lib-1-rc3c. This release fixes a security problem where opening a malicious MRL could write to system (or other) files. For detailed information, see: http://xinehq.de Thanks to Dario Nicodemi for the heads-up on this advisory. (* Security fix *) patches/packages/xine-ui-0.99.1-i686-1.tgz: Upgraded to xine-ui-0.99.1, which fixes a similar MRL security issue. For details, see: http://xinehq.de Thanks again to Dario Nicodemi. (* Security fix *) +--------------------------+ WHERE TO FIND THE NEW PACKAGES: +-----------------------------+ Updated packages for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/xine-ui-0.99.1-i686-1.tgz Updated packages for Slackware -current: MD5 SIGNATURES: +-------------+ Slackware 9.1 packages: 68b21648a6cd97728e616343aac98ebc xine-lib-1rc3c-i686-1.tgz 0bac6817cc73f31a3a5f1eddaf6f3d87 xine-ui-0.99.1-i686-1.tgz Slackware -current packages: bddb07adb56f7fe612ba857c31fb6cbb xine-lib-1rc3c-i686-2.tgz c8786e6b23c4d6e824d27e83e3ba6cdb xine-ui-0.99.1-i686-1.tgz INSTALLATION INSTRUCTIONS: +------------------------+ Upgrade the packages as root: # upgradepkg xine-lib-1rc3c-i686-1.tgz xine-ui-0.99.1-i686-1.tgz +-----+ . Updates addressing xine vulnerabilities in Slackware 9.1 and -current are now accessible, complete with comprehensive guidelines.. Slackware packages,xine update,system security,software patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.